DSA-2022-210: Dell CloudLink Security Update for Multiple Security Vulnerabilities
Summary: Dell CloudLink remediation is available for SSM Agent console access security issue that may be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2022-34380 |
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability as it allows attacker to take control of the system. |
9.1 |
| Third-party Component |
CVEs |
More information |
| Ubuntu 16.04 ESM: GNU C Library vulnerabilities (USN-5310-2) |
See NVD (http://nvd.nist.gov/ |
|
| Ubuntu 16.04 ESM: klibc vulnerabilities (USN-5379-1) |
||
| Ubuntu 16.04 ESM: Rsyslog vulnerability (USN-5404-2) |
||
| Ubuntu 16.04 ESM: Linux kernel vulnerabilities (USN-5413-1) |
||
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2022-34380 |
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability as it allows attacker to take control of the system. |
9.1 |
| Third-party Component |
CVEs |
More information |
| Ubuntu 16.04 ESM: GNU C Library vulnerabilities (USN-5310-2) |
See NVD (http://nvd.nist.gov/ |
|
| Ubuntu 16.04 ESM: klibc vulnerabilities (USN-5379-1) |
||
| Ubuntu 16.04 ESM: Rsyslog vulnerability (USN-5404-2) |
||
| Ubuntu 16.04 ESM: Linux kernel vulnerabilities (USN-5413-1) |
||
Affected Products & Remediation
| Product | Affected Versions | Updated Version | Link to Update |
| Dell Cloudlink | Versions before 7.1.4 | 7.1.4 | CloudLink Downloads |
| Product | Affected Versions | Updated Version | Link to Update |
| Dell Cloudlink | Versions before 7.1.4 | 7.1.4 | CloudLink Downloads |
Workarounds & Mitigations
Customers can disable SSM Agent following instructions in the Dell article 200819: CloudLink : Disable AWS console access to CloudLink OS.
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2022-08-01 |
Initial Release |