DSA-2023-249: Security Update for Dell Connectrix (Brocade) for Multiple Vulnerabilities
Summary: Dell Connectrix (Brocade) remediation is available for Fabric OS (FOS) multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Critical
Details
| Third-party Component | CVEs | More Information |
|---|---|---|
| OpenSSL | CVE-2021-23841, CVE-2022-0778 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| Apache httpd | CVE-2021-34798, CVE-2021-39275 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| FOS | CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| EZServer | CVE-2022-33186 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Affected Products & Remediation
| CVEs Addressed | Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 9.1.1 | Version 9.1.1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 9.0.1e | Version 9.0.1e or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 8.2.3c | Version 8.2.3c or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 8.2.0_CBN5 | Version 8.2.0_CBN5 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 7.4.2j | Version 7.4.2j or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-39275, CVE-2022-0778 | Connectrix B-Series | FOS | Versions prior to 9.2.0 | Version 9.2.0 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-0778 | Connectrix B-Series | FOS | Versions prior to 8.2.3d | Version 8.2.3d or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183 | Connectrix B-Series | FOS | Versions prior to 9.1.0b | Version 9.1.0b or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 9.1.1_01 | Version 9.1.1_01 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 9.0.1e1 | Version 9.0.1e1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 8.2.3c1 | Version 8.2.3c1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 7.4.2j1 | Version 7.4.2j1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVEs Addressed | Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 9.1.1 | Version 9.1.1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 9.0.1e | Version 9.0.1e or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 8.2.3c | Version 8.2.3c or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 8.2.0_CBN5 | Version 8.2.0_CBN5 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 | Connectrix B-Series | FOS | Versions prior to 7.4.2j | Version 7.4.2j or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2021-39275, CVE-2022-0778 | Connectrix B-Series | FOS | Versions prior to 9.2.0 | Version 9.2.0 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-0778 | Connectrix B-Series | FOS | Versions prior to 8.2.3d | Version 8.2.3d or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183 | Connectrix B-Series | FOS | Versions prior to 9.1.0b | Version 9.1.0b or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 9.1.1_01 | Version 9.1.1_01 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 9.0.1e1 | Version 9.0.1e1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 8.2.3c1 | Version 8.2.3c1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
| CVE-2022-33186 | Connectrix B-Series | FOS | Versions prior to 7.4.2j1 | Version 7.4.2j1 or later | https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview |
Workarounds & Mitigations
| CVE ID | Workaround and Mitigation |
|---|---|
| CVE-2022-33186 | EZServer Component - To remove any exposure to this vulnerability, Brocade Fabric OS (FOS) switch administrators must disable EZServer support or upgrade to a version of Brocade Fabric OS that has the EZServer module removed. Disabling EZServer is accomplished through the use of CLI command configurechassis. Disabling the EZServer in the switch configuration will prevent any exposure to this vulnerability. This option is only available on Brocade Fabric OS versions v8.1.0b and higher. Customers running on older versions of Brocade Fabric OS, including v7.4.2j, do not have this option and must upgrade to Brocade Fabric OS v7.4.2j1 to protect their switches. |
Revision History
| Revision | Date | Description |
| 1.0 | 2023-08-08 | Initial Release |
| 2.0 | 2025-02-11 | Updated for enhanced format presentation with no changes to content |
Related Information
Legal Disclaimer
Affected Products
Connectrix B-Series, Connectrix DS-6505B, Connectrix DS-6510B, Connectrix DS-6520B, Connectrix DS-6610B, Connectrix DS-6620B, Connectrix DS-6620B-V2, Connectrix DS-6630B, Connectrix DS-6630B-V2, Connectrix DS-7720B, Connectrix DS-7730B
, Connectrix DS 300B, Connectrix ED-DCX6-4B, Connectrix ED-DCX6-8B, Connectrix ED-DCX7-4B, Connectrix ED-DCX7-8B, Connectrix ED-DCX8510-4B, Connectrix ED-DCX8510-8B, Connectrix MP-7800B, Connectrix MP-7810B, Connectrix MP-7840B, Connectrix SANnav
...
Article Properties
Article Number: 000216161
Article Type: Dell Security Advisory
Last Modified: 17 Feb 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.