DSA-2023-249: Security Update for Dell Connectrix (Brocade) for Multiple Vulnerabilities

Summary: Dell Connectrix (Brocade) remediation is available for Fabric OS (FOS) multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Third-party Component  CVEs  More Information 
OpenSSL CVE-2021-23841, CVE-2022-0778 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
Apache httpd CVE-2021-34798, CVE-2021-39275 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
FOS CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
EZServer CVE-2022-33186 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs Addressed Product Software/Firmware Affected Versions Remediated Versions Link
CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 9.1.1 Version 9.1.1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 9.0.1e Version 9.0.1e or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 8.2.3c Version 8.2.3c or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 8.2.0_CBN5 Version 8.2.0_CBN5 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 7.4.2j Version 7.4.2j or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-39275, CVE-2022-0778 Connectrix B-Series FOS Versions prior to 9.2.0 Version 9.2.0 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-0778 Connectrix B-Series FOS Versions prior to 8.2.3d Version 8.2.3d or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183 Connectrix B-Series FOS Versions prior to 9.1.0b Version 9.1.0b or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 9.1.1_01 Version 9.1.1_01 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 9.0.1e1 Version 9.0.1e1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 8.2.3c1 Version 8.2.3c1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 7.4.2j1 Version 7.4.2j1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVEs Addressed Product Software/Firmware Affected Versions Remediated Versions Link
CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 9.1.1 Version 9.1.1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-0778, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 9.0.1e Version 9.0.1e or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 8.2.3c Version 8.2.3c or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 8.2.0_CBN5 Version 8.2.0_CBN5 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-23841, CVE-2021-34798, CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183, CVE-2022-33184 Connectrix B-Series FOS Versions prior to 7.4.2j Version 7.4.2j or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2021-39275, CVE-2022-0778 Connectrix B-Series FOS Versions prior to 9.2.0 Version 9.2.0 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-0778 Connectrix B-Series FOS Versions prior to 8.2.3d Version 8.2.3d or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-28170, CVE-2022-33179, CVE-2022-33180, CVE-2022-33181, CVE-2022-33182, CVE-2022-33183 Connectrix B-Series FOS Versions prior to 9.1.0b Version 9.1.0b or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 9.1.1_01 Version 9.1.1_01 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 9.0.1e1 Version 9.0.1e1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 8.2.3c1 Version 8.2.3c1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview
CVE-2022-33186 Connectrix B-Series FOS Versions prior to 7.4.2j1 Version 7.4.2j1 or later https://www.dell.com/support/home/product-support/product/connectrix-b-series-hardware/overview

Workarounds & Mitigations

CVE ID Workaround and Mitigation
CVE-2022-33186 EZServer Component - To remove any exposure to this vulnerability, Brocade Fabric OS (FOS) switch administrators must disable EZServer support or upgrade to a version of Brocade Fabric OS that has the EZServer module removed.
Disabling EZServer is accomplished through the use of CLI command configurechassis.  Disabling the EZServer in the switch configuration will prevent any exposure to this vulnerability.  
This option is only available on Brocade Fabric OS versions v8.1.0b and higher.  Customers running on older versions of Brocade Fabric OS, including v7.4.2j, do not have this option and must upgrade to Brocade Fabric OS v7.4.2j1 to protect their switches.

Revision History

RevisionDateDescription
1.02023-08-08Initial Release
2.02025-02-11Updated for enhanced format presentation with no changes to content

Related Information

Affected Products

Connectrix B-Series, Connectrix DS-6505B, Connectrix DS-6510B, Connectrix DS-6520B, Connectrix DS-6610B, Connectrix DS-6620B, Connectrix DS-6620B-V2, Connectrix DS-6630B, Connectrix DS-6630B-V2, Connectrix DS-7720B, Connectrix DS-7730B , Connectrix DS 300B, Connectrix ED-DCX6-4B, Connectrix ED-DCX6-8B, Connectrix ED-DCX7-4B, Connectrix ED-DCX7-8B, Connectrix ED-DCX8510-4B, Connectrix ED-DCX8510-8B, Connectrix MP-7800B, Connectrix MP-7810B, Connectrix MP-7840B, Connectrix SANnav ...
Article Properties
Article Number: 000216161
Article Type: Dell Security Advisory
Last Modified: 17 Feb 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.