Impact
Medium
Details
Third-party Component |
CVE(s) |
More information |
iDRAC |
CVE-2020-5344 |
7.0 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H) DSA-2020-063 iDRAC Buffer Overflow Vulnerability |
Third-party Component |
CVE(s) |
More information |
iDRAC |
CVE-2020-5344 |
7.0 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H) DSA-2020-063 iDRAC Buffer Overflow Vulnerability |
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Affected models:
Dell Data Domain DD3300 Appliance
- Dell Data Domain OS versions prior to DDOS 6.1.2.70
- Dell Data Domain OS versions prior to DDOS 6.2.1.0
- Dell Data Domain OS versions prior to DDOS 7.0.0.20
- Dell Data Domain OS versions prior to DDOS 7.1.0.20
- Dell Data Domain OS versions prior to DDOS 7.2.0.5
Dell Data Domain DD9900 Appliance
Dell Data Domain DD9400 Appliance
Dell Data Domain DD6900 Appliance
- Dell Data Domain OS versions prior to DDOS 7.1.0.10
Dell PowerProtect X400 Appliance
- Dell PowerProtect OSP versions prior to 3.0
Remediation:
The following Dell Data Domain releases addresses this vulnerability:
- Dell Data Domain OS version DDOS 6.1.2.70
- Dell Data Domain OS version DDOS 6.2.1.0
- Dell Data Domain OS version DDOS 7.0.0.20
- Dell Data Domain OS version DDOS 7.1.0.10
- Dell Data Domain OS version DDOS 7.1.0.20
- Dell Data Domain OS version DDOS 7.2.0.5
- Dell PowerProtect OSP version 3.0
Dell recommends all customers upgrade at the earliest opportunity.
Affected models:
Dell Data Domain DD3300 Appliance
- Dell Data Domain OS versions prior to DDOS 6.1.2.70
- Dell Data Domain OS versions prior to DDOS 6.2.1.0
- Dell Data Domain OS versions prior to DDOS 7.0.0.20
- Dell Data Domain OS versions prior to DDOS 7.1.0.20
- Dell Data Domain OS versions prior to DDOS 7.2.0.5
Dell Data Domain DD9900 Appliance
Dell Data Domain DD9400 Appliance
Dell Data Domain DD6900 Appliance
- Dell Data Domain OS versions prior to DDOS 7.1.0.10
Dell PowerProtect X400 Appliance
- Dell PowerProtect OSP versions prior to 3.0
Remediation:
The following Dell Data Domain releases addresses this vulnerability:
- Dell Data Domain OS version DDOS 6.1.2.70
- Dell Data Domain OS version DDOS 6.2.1.0
- Dell Data Domain OS version DDOS 7.0.0.20
- Dell Data Domain OS version DDOS 7.1.0.10
- Dell Data Domain OS version DDOS 7.1.0.20
- Dell Data Domain OS version DDOS 7.2.0.5
- Dell PowerProtect OSP version 3.0
Dell recommends all customers upgrade at the earliest opportunity.
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Affected Products
Data Domain, Data Domain, Data Domain Boost – File System, Data Domain Boost - Open Storage, Data Domain Deduplication Storage Systems, DD Boost for Enterprise Applications, DD OS, DD OS 4.9, PowerProtect Data Domain Management Center
Products
DD OS 6.2, DD OS 5.0, DD OS 5.2, DD OS 5.3, DD OS 5.4, DD OS 5.5, DD OS 5.6, DD OS 6.0, DD OS 6.1, DD OS 7.0, DD OS 7.2, DD OS Licensed Features, PowerProtect Data Manager, Product Security Information