Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

DSA-2021-311: Dell EMC XC Series and Core Appliance Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105)

Summary: Dell EMC XC Series and Core Appliance remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

This article applies to   This article does not apply to 

Impact

Critical

Details

Third-party Component CVEs More information
Apache Log4j CVE-2021-44228, CVE-2021-45046, CVE-2021-45105  Apache Log4j Remote Code Execution
Third-party Component CVEs More information
Apache Log4j CVE-2021-44228, CVE-2021-45046, CVE-2021-45105  Apache Log4j Remote Code Execution
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

The table below shows the affected products and components impacted for the Dell EMC XC Series and Core Appliances.
 
Product  Affected Versions  Updated Versions  Link to Update 
Nutanix AOS 6.0 STS (Short Term Support) Branch only
 
STS versions before 6.0.2.4  6.0.2.4 Patched in AOS 6.0.2.4, available from the Nutanix Support Portal (https://my.nutanix.com [Nutanix login required])
Nutanix Objects
 
All versions  No patch; mitigation only  Mitigation is available.
See Nutanix article: https://portal.nutanix.com/kb/12482

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.


Information with solid fillNOTE: To determine if additional features and software purchased directly from Nutanix are affected, see Nutanix Advisory: Nutanix Security Advisory #0023.
 
Dell EMC PowerTools (PTAgent) and iDRAC Service Module (iSM) software components that are included with XC Series and Core Appliances are unaffected.
The table below shows the affected products and components impacted for the Dell EMC XC Series and Core Appliances.
 
Product  Affected Versions  Updated Versions  Link to Update 
Nutanix AOS 6.0 STS (Short Term Support) Branch only
 
STS versions before 6.0.2.4  6.0.2.4 Patched in AOS 6.0.2.4, available from the Nutanix Support Portal (https://my.nutanix.com [Nutanix login required])
Nutanix Objects
 
All versions  No patch; mitigation only  Mitigation is available.
See Nutanix article: https://portal.nutanix.com/kb/12482

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.


Information with solid fillNOTE: To determine if additional features and software purchased directly from Nutanix are affected, see Nutanix Advisory: Nutanix Security Advisory #0023.
 
Dell EMC PowerTools (PTAgent) and iDRAC Service Module (iSM) software components that are included with XC Series and Core Appliances are unaffected.

Workarounds & Mitigations

Additional workarounds and mitigations for the Nutanix Software available at Nutanix Security Advisory #0023.

Revision History

RevisionDateDescription
1.02021-12-29Initial Release

Related Information

Affected Products

XC Core Systems, XC Series Appliances

Products

Dell EMC XC Core XCXR2, Dell EMC XC Core XC450, Dell EMC XC Core XC650, Dell EMC XC Core XC6520, Dell EMC XC Core XC740xd2, Dell EMC XC Core XC750, Dell EMC XC Core XC750xa, Dell EMC XC Series XC640 Appliance, Dell EMC XC Core XC640 System , Dell EMC XC Series XC6420 Appliance, Dell EMC XC Core 6420 System, Dell EMC XC Series XC740xd Appliance, Dell EMC XC Core XC740xd System, Dell EMC XC Series XC940 Appliance, Dell EMC XC Core XC940 System, Product Security Information, Dell EMC XC Core XC7525 ...