Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

Article Number: 000206603


DSA-2022-199: Dell Avamar Security Update for Avamar Data Storage GEN4T FIRMWARE 18.11 BUNDLE Security Update Vulnerabilities

Summary: Dell Avamar remediation is available for Avamar Data Storage GEN4T FIRMWARE 18.11 BUNDLE Security that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Third-party Component CVEs More information
ADS Gen4T AMI BIOS
SND Europa 2U
CVE-2021-28211, CVE-2021-28210 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS - SND - Europa 2U CVE-2021-0154, CVE-2021-0153, CVE-2021-33123,
CVE-2021-0190, CVE-2021-33124, CVE-2021-0155
See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Europa 2U
Haswell EP, CPUID: 306F2
CVE-2020-12357, CVE-2020-12360 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen 4T,
Europa 2U, BSSA API
CVE-2021-0144 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen4T Europa 2U
Haswell EP, CPUID: 306F2
CVE-2021-0092, CVE-2021-0099, CVE-2021-0103,
CVE-2021-0107, CVE-2021-0111, CVE-2021-0114,
CVE-2021-0115, CVE-2021-0116, CVE-2021-0117,
CVE-2021-0118
CVE-2021-0060
See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen4T
Europa 2U
CVE-2020-0591, CVE-2020-0592 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen4T: Europa 2U CVE-2020-8764, CVE-2020-8738, CVE-2020-8740 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
Third-party Component CVEs More information
ADS Gen4T AMI BIOS
SND Europa 2U
CVE-2021-28211, CVE-2021-28210 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS - SND - Europa 2U CVE-2021-0154, CVE-2021-0153, CVE-2021-33123,
CVE-2021-0190, CVE-2021-33124, CVE-2021-0155
See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Europa 2U
Haswell EP, CPUID: 306F2
CVE-2020-12357, CVE-2020-12360 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen 4T,
Europa 2U, BSSA API
CVE-2021-0144 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen4T Europa 2U
Haswell EP, CPUID: 306F2
CVE-2021-0092, CVE-2021-0099, CVE-2021-0103,
CVE-2021-0107, CVE-2021-0111, CVE-2021-0114,
CVE-2021-0115, CVE-2021-0116, CVE-2021-0117,
CVE-2021-0118
CVE-2021-0060
See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen4T
Europa 2U
CVE-2020-0591, CVE-2020-0592 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
ADS Gen4T: Europa 2U CVE-2020-8764, CVE-2020-8738, CVE-2020-8740 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed  Product Affected Versions Updated Versions Link to Update
See list above Dell Avamar Data Store Gen4T All versions on Avamar Data Store Gen4T Avamar Data Store Gen4T with Firmware Bundle Customers should contact support to install Firmware 18.11 Bundle release.
See list above Dell ADS Gen4T PowerProtect DP8300, PowerProtect DP8400, PowerProtect DP8800, and PowerProtect DP8900 PowerProtect DP8300, PowerProtect DP8400, PowerProtect DP8800, and PowerProtect DP8900with Firmware Bundle Customers should contact support to install Firmware 18.11 Bundle release.
CVEs Addressed  Product Affected Versions Updated Versions Link to Update
See list above Dell Avamar Data Store Gen4T All versions on Avamar Data Store Gen4T Avamar Data Store Gen4T with Firmware Bundle Customers should contact support to install Firmware 18.11 Bundle release.
See list above Dell ADS Gen4T PowerProtect DP8300, PowerProtect DP8400, PowerProtect DP8800, and PowerProtect DP8900 PowerProtect DP8300, PowerProtect DP8400, PowerProtect DP8800, and PowerProtect DP8900with Firmware Bundle Customers should contact support to install Firmware 18.11 Bundle release.

Workarounds and Mitigations

To resolve these issues, open a service request to Dell Support team to install Avamar Gen4T 18.11 firmware update (hotfix 336357).

Revision History

RevisionDateDescription
1.02022-12-19 Initial Release

Related Information


Article Properties


Affected Product

Avamar, Avamar, Avamar Data Store Gen4T, Avamar Server, PowerProtect DP8300, PowerProtect DP8800, PowerProtect DP8400, PowerProtect DP8900, Product Security Information

Last Published Date

10 Jan 2023

Version

4

Article Type

Dell Security Advisory