DSA-2020-078: Dell EMC Integrated Data Protection Appliance Security Update for Multiple Third Party Components
Impact
High
Details
Summary:
Multiple components within Dell EMC Integrated Data Protection Appliance require a security update to address various vulnerabilities.
The components are updated for the following vulnerabilities:
-
OpenSLP
CVE-2019-5544
-
Oracle JRE
CVE-2020-2674 CVE-2020-2550
- PowerEdge BIOS firmware
CVE-2019-0124 CVE-2019-0151 CVE-2019-0123 CVE-2019-0152
CVE-2019-11136 CVE-2019-11137 CVE-2019-11135 CVE-2019-11139
CVE-2019-11090 CVE-2019-11109
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
The components are updated for the following vulnerabilities:
-
OpenSLP
CVE-2019-5544
-
Oracle JRE
CVE-2020-2674 CVE-2020-2550
- PowerEdge BIOS firmware
CVE-2019-0124 CVE-2019-0151 CVE-2019-0123 CVE-2019-0152
CVE-2019-11136 CVE-2019-11137 CVE-2019-11135 CVE-2019-11139
CVE-2019-11090 CVE-2019-11109
For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.
To search for a particular CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search.
Affected Products & Remediation
Affected products:
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4
Remediation:
The following Dell EMC Integrated Data Protection Appliance release addresses these vulnerabilities:
-
Dell EMC Integrated Data Protection Appliance 2.5
https://download.emc.com/downloads/DL97800_IDPA-2.5-Upgrade.tar.gz
Note: Integrated Data Protection Appliance 2.0 customers will have to upgrade to version 2.1 first, then to version 2.3.1, and then to 2.5 in order to address these vulnerabilities.
PowerEdge BIOS Firmware fixes are applied by Support. To upgrade your Dell EMC Integrated Data Protection Appliance BIOS firmware, contact Dell EMC Integrated Data Protection Appliance Customer Support at www.support.dell.com
Dell EMC recommends all customers upgrade at the earliest opportunity.
Affected products:
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4
Remediation:
The following Dell EMC Integrated Data Protection Appliance release addresses these vulnerabilities:
-
Dell EMC Integrated Data Protection Appliance 2.5
https://download.emc.com/downloads/DL97800_IDPA-2.5-Upgrade.tar.gz
Note: Integrated Data Protection Appliance 2.0 customers will have to upgrade to version 2.1 first, then to version 2.3.1, and then to 2.5 in order to address these vulnerabilities.
PowerEdge BIOS Firmware fixes are applied by Support. To upgrade your Dell EMC Integrated Data Protection Appliance BIOS firmware, contact Dell EMC Integrated Data Protection Appliance Customer Support at www.support.dell.com
Dell EMC recommends all customers upgrade at the earliest opportunity.