Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000181654


DSA-2021-004: Dell EMC Search Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell EMC Search contains remediation for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

 
Third-Party Component
 
CVE(s) More information
Grub2 CVE-2020-10713 https://www.suse.com/security/cve/CVE-2020-10713/
Oracle JRE CVE-2020-14664 https://www.oracle.com/security-alerts/cpujul2020.html#AppendixJAVA
CVE-2020-14583
CVE-2020-14593
CVE-2020-14562
CVE-2020-14621
CVE-2020-14556
CVE-2020-14573
CVE-2020-14581
CVE-2020-14578
CVE-2020-14579
CVE-2020-14577

 
Third-Party Component
 
CVE(s) More information
Grub2 CVE-2020-10713 https://www.suse.com/security/cve/CVE-2020-10713/
Oracle JRE CVE-2020-14664 https://www.oracle.com/security-alerts/cpujul2020.html#AppendixJAVA
CVE-2020-14583
CVE-2020-14593
CVE-2020-14562
CVE-2020-14621
CVE-2020-14556
CVE-2020-14573
CVE-2020-14581
CVE-2020-14578
CVE-2020-14579
CVE-2020-14577

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

 
CVE(s) Addressed  Product Affected Version(s) Updated Version(s) Link to Update  
CVE-2020-10713
CVE-2020-14664
CVE-2020-14583
CVE-2020-14593
CVE-2020-14562
CVE-2020-14621
CVE-2020-14556
CVE-2020-14573
CVE-2020-14581
CVE-2020-14578
CVE-2020-14579
CVE-2020-14577
Dell EMC Search versions prior to 19.4


 
For Dell EMC Search version 18.0 to 19.3, an upgrade to release 19.4 is required to receive the security update. https://www.dell.com/support/home/en-us/product-support/product/data-protection-search/drivers  
To remediate the vulnerabilities in IDPA, first upgrade to IDPA 2.6 and then upgrade Search component in IDPA to Dell EMC Search version 19.4  
versions prior to 2.6.1  
Dell EMC iDPA  
 
 
CVE(s) Addressed  Product Affected Version(s) Updated Version(s) Link to Update  
CVE-2020-10713
CVE-2020-14664
CVE-2020-14583
CVE-2020-14593
CVE-2020-14562
CVE-2020-14621
CVE-2020-14556
CVE-2020-14573
CVE-2020-14581
CVE-2020-14578
CVE-2020-14579
CVE-2020-14577
Dell EMC Search versions prior to 19.4


 
For Dell EMC Search version 18.0 to 19.3, an upgrade to release 19.4 is required to receive the security update. https://www.dell.com/support/home/en-us/product-support/product/data-protection-search/drivers  
To remediate the vulnerabilities in IDPA, first upgrade to IDPA 2.6 and then upgrade Search component in IDPA to Dell EMC Search version 19.4  
versions prior to 2.6.1  
Dell EMC iDPA  
 

Workarounds and Mitigations

None

Revision History

RevisionDateDescription
1.02021-01-06Initial Release

Related Information


Article Properties


Affected Product

Data Protection Search, PowerProtect Data Protection Software

Last Published Date

22 May 2021

Version

2

Article Type

Dell Security Advisory