Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000196624


DSA-2022-045: Dell EMC VxRail Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell EMC VxRail remediation is available for multiple security vulnerabilities that may potentially be exploited by malicious users to compromise the affected system.

Article Content


Impact

Critical

Details

Third-party Component CVEs More Information
VMware vCenter CVE-2021-44228 Apache Log4j critical vulnerabilities. For more details, see VMSA-2021-0028.
CVE-2021-45046
CVE-2021-45105
VMware ESXi CVE-2021-22045 Important Heap-overflow vulnerability. For more details, see VMSA-2022-0001.
CVE-2021-22040 Multiple critical access vulnerabilities. For more details, see VMSA-2022-0004.
CVE-2021-22041
CVE-2021-22050
Intel Solid State Drive (SSD) CVE-2021-0148 DSA-2022-027
Third-party Component CVEs More Information
VMware vCenter CVE-2021-44228 Apache Log4j critical vulnerabilities. For more details, see VMSA-2021-0028.
CVE-2021-45046
CVE-2021-45105
VMware ESXi CVE-2021-22045 Important Heap-overflow vulnerability. For more details, see VMSA-2022-0001.
CVE-2021-22040 Multiple critical access vulnerabilities. For more details, see VMSA-2022-0004.
CVE-2021-22041
CVE-2021-22050
Intel Solid State Drive (SSD) CVE-2021-0148 DSA-2022-027

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Updated Versions
Dell EMC VxRail Appliance 4.5.x versions before 4.5.471 4.5.471
Product Affected Versions Updated Versions
Dell EMC VxRail Appliance 4.5.x versions before 4.5.471 4.5.471

Workarounds and Mitigations

Product Affected Versions CVE Identifier Updated Versions Workarounds
Dell VxRail 4.5.x versions before 4.5.471 CVE-2021-0148 4.5.471 INTEL-SA-00535

Revision History

RevisionDateDescription
1.02022-02-22Initial Release
1.12022-04-28Added Intel Workaround

Related Information

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide


The information in this Dell Technologies Security Advisory should be read and used to assist in avoiding situations that may arise from the problems described herein. Dell Technologies distributes Security Advisories to bring important security information to the attention of users of the affected product(s). Dell Technologies assesses the risk based on an average of risks across a diverse set of installed systems and may not represent the actual risk to your local installation and individual environment. It is recommended that all users determine the applicability of this information to their individual environments and take appropriate actions. The information set forth herein is provided "as is" without warranty of any kind. Dell Technologies expressly disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall Dell Technologies, its affiliates or suppliers, be liable for any damages whatsoever arising from or related to the information contained herein or actions that you decide to take based thereon, including any direct, indirect, incidental, consequential, loss of business profits or special damages, even if Dell Technologies, its affiliates or suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation shall apply to the extent permissible under law.

Article Properties


Affected Product

VxRail, CloudArray Virtual Edition for VxRail Appliance, Product Security Information, VMWare Cloud on Dell EMC VxRail E560F, VMWare Cloud on Dell EMC VxRail E560N, VxRail 460 and 470 Nodes, VxRail Appliance Family, VxRail Appliance SeriesVxRail, CloudArray Virtual Edition for VxRail Appliance, Product Security Information, VMWare Cloud on Dell EMC VxRail E560F, VMWare Cloud on Dell EMC VxRail E560N, VxRail 460 and 470 Nodes, VxRail Appliance Family, VxRail Appliance Series, VxRail G410, VxRail G Series Nodes, VxRail D Series Nodes, VxRail D560, VxRail D560F, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560F, VxRail E560N, VxRail E660, VxRail E660F, VxRail E660N, VxRail E665F, VxRail E665N, VxRail G560, VxRail G560F, VxRail Gen2 Hardware, VxRail P Series Nodes, VxRail P470, VxRail P570, VxRail P570F, VxRail P580N, VXRAIL P670F, VxRail P675F, VxRail P675N, VxRail S Series Nodes, VxRail S470, VxRail S570, VxRail S670, VxRail Software, VxRail V Series Nodes, VxRail V470, VxRail V570, VxRail V570F, VXRAIL V670FSee more

Last Published Date

28 Apr 2022

Version

2

Article Type

Dell Security Advisory