Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

Article Number: 000202540


DSA-2022-241: Dell EMC PowerFlex Rack Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell EMC PowerFlex Rack remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Component  CVEs More information
VMware vCenter Server CVE-2022-22948 VMSA-2022-0009
Intel CVE-2021-0200 Intel-SA-00554
CVE-2021-33058
CVE-2021-33059
CVE-2021-0197 Intel-SA-00555
CVE-2021-0198
CVE-2021-0199
CVE-2021-33061 Intel-SA-00571
Dell PowerEdge BIOS CVE-2021-33117 DSA-2022-127
CVE-2022-0004
CVE-2022-0005
CVE-2021-21131
CVE-2021-21136
CVE-2021-0154
CVE-2021-0153
CVE-2021-33123
CVE-2021-0190
CVE-2021-33122
CVE-2021-0189 
CVE-2021-33124
CVE-2021-33103
CVE-2021-0159
CVE-2021-0188
CVE-2021-0155 
CVE-2022-21123 DSA-2022-161
CVE-2022-21125
CVE-2022-21127
CVE-2022-21166
CVE-2019-14584 DSA-2022-088
CVE-2021-28210
CVE-2021-28211
Dell PowerEdge Server CVE-2021-33078 DSA-2022-128
CVE-2021-33077
CVE-2021-33080
CVE-2021-33074
CVE-2021-33069
CVE-2021-33075
CVE-2021-33083
CVE-2021-33082
Dell iDRAC CVE-2022-0778 DSA-2022-154
CVE-2022-24423 DSA-2022-069
Embedded OS CVE-2021-3695 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
CVE-2021-3696
CVE-2021-3697
CVE-2021-3981
CVE-2022-28733
CVE-2022-28734
CVE-2022-28735
CVE-2022-28736
CVE-2022-28737
Component  CVEs More information
VMware vCenter Server CVE-2022-22948 VMSA-2022-0009
Intel CVE-2021-0200 Intel-SA-00554
CVE-2021-33058
CVE-2021-33059
CVE-2021-0197 Intel-SA-00555
CVE-2021-0198
CVE-2021-0199
CVE-2021-33061 Intel-SA-00571
Dell PowerEdge BIOS CVE-2021-33117 DSA-2022-127
CVE-2022-0004
CVE-2022-0005
CVE-2021-21131
CVE-2021-21136
CVE-2021-0154
CVE-2021-0153
CVE-2021-33123
CVE-2021-0190
CVE-2021-33122
CVE-2021-0189 
CVE-2021-33124
CVE-2021-33103
CVE-2021-0159
CVE-2021-0188
CVE-2021-0155 
CVE-2022-21123 DSA-2022-161
CVE-2022-21125
CVE-2022-21127
CVE-2022-21166
CVE-2019-14584 DSA-2022-088
CVE-2021-28210
CVE-2021-28211
Dell PowerEdge Server CVE-2021-33078 DSA-2022-128
CVE-2021-33077
CVE-2021-33080
CVE-2021-33074
CVE-2021-33069
CVE-2021-33075
CVE-2021-33083
CVE-2021-33082
Dell iDRAC CVE-2022-0778 DSA-2022-154
CVE-2022-24423 DSA-2022-069
Embedded OS CVE-2021-3695 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
CVE-2021-3696
CVE-2021-3697
CVE-2021-3981
CVE-2022-28733
CVE-2022-28734
CVE-2022-28735
CVE-2022-28736
CVE-2022-28737
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

 Product  Affected  Version(s)  Updated   Version(s)  Link to Update
 PowerFlex   Rack  RCM Versions   prior to 3.3.12.0

 RCM Versions   prior to 3.4.7.0

 RCM Versions   prior to 3.5.7.0

 RCM Versions   prior to 3.6.3.0

 RCM Versions   prior to 3.7.0.0
 
 3.7.0.0


 3.4.7.0


 3.5.7.0


 3.6.3.0


 3.7.0.0
 For RCM release information: https://cicodeportal.dell.com/#/home
 
 For RCM download: https://vce.flexnetoperations.com/control/vcec/product?plneID=740417
 
 Product  Affected  Version(s)  Updated   Version(s)  Link to Update
 PowerFlex   Rack  RCM Versions   prior to 3.3.12.0

 RCM Versions   prior to 3.4.7.0

 RCM Versions   prior to 3.5.7.0

 RCM Versions   prior to 3.6.3.0

 RCM Versions   prior to 3.7.0.0
 
 3.7.0.0


 3.4.7.0


 3.5.7.0


 3.6.3.0


 3.7.0.0
 For RCM release information: https://cicodeportal.dell.com/#/home
 
 For RCM download: https://vce.flexnetoperations.com/control/vcec/product?plneID=740417
 

Revision History

 Revision  Date Description
 1.0 2022-08-18  Initial Release
 2.0 2022-08-22 Updated Section “Affected Products and Remediation”
 3.0 2022-09-01 Updated Section “Impact” to High
 4.0 2022-09-29 Updated Section “Affected Products and Remediation”

Related Information


Article Properties


Affected Product

PowerFlex rack, PowerFlex rack connectivity, Product Security Information

Last Published Date

29 Sep 2022

Version

4

Article Type

Dell Security Advisory