DSA-2021-165: Dell EMC NetWorker Virtual Edition (NVE) Security Update for Multiple Third-Party Components

Summary: Dell EMC NetWorker Virtual Edition (NVE) remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Third-party Component Propriety Code CVEs  More Information
cyrus-sasl CVE-2019-19906 See NVD (http://nvd.nist.gov/) for individual scores of each CVE.
Dnsmasq CVE-2019-14834
CVE-2020-25681
CVE-2020-25682
CVE-2020-25683
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2020-25687
Xen CVE-2020-25723
CVE-2020-27670
CVE-2020-27671
CVE-2020-28368
CVE-2020-29130
CVE-2020-29484
CVE-2020-29566
CVE-2020-29571
Third-party Component Propriety Code CVEs  More Information
cyrus-sasl CVE-2019-19906 See NVD (http://nvd.nist.gov/) for individual scores of each CVE.
Dnsmasq CVE-2019-14834
CVE-2020-25681
CVE-2020-25682
CVE-2020-25683
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2020-25687
Xen CVE-2020-25723
CVE-2020-27670
CVE-2020-27671
CVE-2020-28368
CVE-2020-29130
CVE-2020-29484
CVE-2020-29566
CVE-2020-29571
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Updated Versions Link to Update
Dell EMC NetWorker Virtual Edition (NVE) 18.1.0, 18.1.0.x, 18.2.0, 18.2.0.x, 19.1.0, 19.1.0.x, 19.1.1.x, 19.2.0, 19.2.0.x, 19.2.1.x, 19.3.0, and 19.3.0.x with base OS image of SUSE Linux Enterprise 11 SP4
 
19.4.0, 19.4.0.1, 19.4.0.2, 19.4.0.3, 19.5.0, and 19.5.0.1 with rollup 2021-R1plus or newer rollup applied. To security update for Dell EMC NetWorker Virtual Edition is customer installable. Refer to the following Knowledge Base article for Security Update (Rollup) Installation:
https://support.emc.com/kb/476507  

To schedule platform security patch installation, or to upgrade your server contact Dell EMC Customer Support at 
https://www.dell.com/support ​​​​​​​
Product Affected Versions Updated Versions Link to Update
Dell EMC NetWorker Virtual Edition (NVE) 18.1.0, 18.1.0.x, 18.2.0, 18.2.0.x, 19.1.0, 19.1.0.x, 19.1.1.x, 19.2.0, 19.2.0.x, 19.2.1.x, 19.3.0, and 19.3.0.x with base OS image of SUSE Linux Enterprise 11 SP4
 
19.4.0, 19.4.0.1, 19.4.0.2, 19.4.0.3, 19.5.0, and 19.5.0.1 with rollup 2021-R1plus or newer rollup applied. To security update for Dell EMC NetWorker Virtual Edition is customer installable. Refer to the following Knowledge Base article for Security Update (Rollup) Installation:
https://support.emc.com/kb/476507  

To schedule platform security patch installation, or to upgrade your server contact Dell EMC Customer Support at 
https://www.dell.com/support ​​​​​​​

Revision History

RevisionDateDescription
1.02021-08-18Initial Release

Related Information

Affected Products

NetWorker, Product Security Information
Article Properties
Article Number: 000190342
Article Type: Dell Security Advisory
Last Modified: 18 Aug 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.