Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000191991


DSA-2021-196: Dell EMC VxRail Appliance Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell EMC VxRail Appliance remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected systems.

Article Content


Impact

Critical

Details

Third-Party Component CVEs Fixed in release: More information
vCenter Server 7.0
 
CVE-2021-22011
CVE-2021-22018
7.0.241 Severity: High, see VMSA-2021-0020
vCenter Server 6.7 CVE-2021-22005 4.7.536 Severity: Critical, see VMSA-2021-0020
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22006
CVE-2021-22007
CVE-2021-22008
CVE-2021-22009
CVE-2021-22010
CVE-2021-22011
CVE-2021-22014
CVE-2021-22015
CVE-2021-22016
CVE-2021-22017
CVE-2021-22019
CVE-2021-22020
4.7.536 Severity: High, see VMSA-2021-0020
vCenter Server 6.5
 
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22008
CVE-2021-22009
CVE-2021-22011
CVE-2021-22012
CVE-2021-22013
CVE-2021-22014
CVE-2021-22015
CVE-2021-22017
CVE-2021-22019
4.5.463 Severity: High, see VMSA-2021-0020
Third-Party Component CVEs Fixed in release: More information
vCenter Server 7.0
 
CVE-2021-22011
CVE-2021-22018
7.0.241 Severity: High, see VMSA-2021-0020
vCenter Server 6.7 CVE-2021-22005 4.7.536 Severity: Critical, see VMSA-2021-0020
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22006
CVE-2021-22007
CVE-2021-22008
CVE-2021-22009
CVE-2021-22010
CVE-2021-22011
CVE-2021-22014
CVE-2021-22015
CVE-2021-22016
CVE-2021-22017
CVE-2021-22019
CVE-2021-22020
4.7.536 Severity: High, see VMSA-2021-0020
vCenter Server 6.5
 
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22008
CVE-2021-22009
CVE-2021-22011
CVE-2021-22012
CVE-2021-22013
CVE-2021-22014
CVE-2021-22015
CVE-2021-22017
CVE-2021-22019
4.5.463 Severity: High, see VMSA-2021-0020

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed Product Affected Versions Updated Versions
See above table Dell EMC VxRail Appliance 7.0.x versions before 7.0.241
4.7.x versions before 4.7.536
4.5.x versions before 4.5.463
 7.0.241
 4.7.536
 4.5.463
CVEs Addressed Product Affected Versions Updated Versions
See above table Dell EMC VxRail Appliance 7.0.x versions before 7.0.241
4.7.x versions before 4.7.536
4.5.x versions before 4.5.463
 7.0.241
 4.7.536
 4.5.463
Revision History

RevisionDateDescription
1.02021-09-23Initial Release
1.12021-10-04Updated to remove CVEs that were fixed in release 7.0.240
1.22021-11-17Updated to clarify affected version numbers

Related Information

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide


Article Properties


Affected Product

VxRail, Product Security Information

Last Published Date

18 Nov 2021

Version

4

Article Type

Dell Security Advisory