DSA-2022-140: Dell Technologies PowerProtect Data Domain Security Update for an iDRAC9 VNC Console Authentication Vulnerability
Summary: Dell Technologies PowerProtect Data Domain remediation is available for an iDRAC9 VNC Console Authentication vulnerability that may be exploited by malicious users to compromise the affected system. ...
Impact
Critical
Details
|
Third-party Component |
CVE |
More information |
|
iDRAC9 |
CVE-2022-24422 |
Dell KB article 199267: DSA-2022-068: Dell iDRAC9 Security Update for an Improper Authentication Vulnerability. |
|
Third-party Component |
CVE |
More information |
|
iDRAC9 |
CVE-2022-24422 |
Dell KB article 199267: DSA-2022-068: Dell iDRAC9 Security Update for an Improper Authentication Vulnerability. |
Affected Products & Remediation
|
Product |
Affected Versions |
Updated Versions |
Link to Update |
|
PowerProtect DD Appliance models: DD3300, DD6400, DD6900/DD9400/DD9900
|
7.0 to 7.8 |
7.9.0.0 and later |
For more details about DDOS versions available for download, see the links below (requires log in to Dell Support to view articles):
|
|
7.7.2 |
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
|
Product |
Affected Versions |
Updated Versions |
Link to Update |
|
PowerProtect DD Appliance models: DD3300, DD6400, DD6900/DD9400/DD9900
|
7.0 to 7.8 |
7.9.0.0 and later |
For more details about DDOS versions available for download, see the links below (requires log in to Dell Support to view articles):
|
|
7.7.2 |
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Workarounds & Mitigations
Note: VNC Server in iDRAC9 is disabled by default.
Disable VNC Server in iDRAC9 UI by Configuration > Virtual Console > VNC Server.
See Dell article 178016: Support for Integrated Dell Remote Access Controller 9 (iDRAC9) for details.
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2022-05-18 |
Initial Release |
| 1.1 | 2022-07-12 | Edited versions in Affected Products and Remediation Table |