DSA-2023-402: Security Update for Dell EMC Enterprise SONiC Distribution Multiple Third-Party Component Vulnerabilities.

Summary: Dell EMC Enterprise SONiC remediation is available for multiple Third-party vulnerabilities.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Third-party Component CVEs More Information
c-ares CVE-2023-31130, CVE-2023-32067
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
cpio CVE-2019-14866, CVE-2021-38185
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libfastjson CVE-2020-12762
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libssh2 CVE-2019-13115, CVE-2019-17498, CVE-2020-22218
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libx11 CVE-2023-3138
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libxpm CVE-2022-4883, CVE-2022-44617, CVE-2022-46285
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
openssh CVE-2023-38408
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
openssl CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-2650, CVE-2023-3446, CVE-2023-3817
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
Python2.7 CVE-2021-23336, CVE-2022-0391, CVE-2022-48560, CVE-2022-48565, CVE-2022-48566, CVE-2023-24329, CVE-2023-40217
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
Python3.7 CVE-2015-20107, CVE-2020-10735, CVE-2021-3426, CVE-2021-3733, CVE-2021-3737, CVE-2021-4189, CVE-2022-45061
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
systemd CVE-2022-3821
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
vim CVE-2022-4141, CVE-2023-0054, CVE-2023-1175, CVE-2023-2610
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Remediated Versions Link
Dell EMC Enterprise SONiC Distribution Versions prior to 4.1.2  4.1.2  Enterprise SONiC OS 4.1.2 gns3
Product Affected Versions Remediated Versions Link
Dell EMC Enterprise SONiC Distribution Versions prior to 4.1.2  4.1.2  Enterprise SONiC OS 4.1.2 gns3

Revision History

RevisionDateDescription
1.02023-11-13Initial Release
2.02023-12-05Formatting change with no content changes

Related Information

Affected Products

Enterprise SONiC Distribution
Article Properties
Article Number: 000219487
Article Type: Dell Security Advisory
Last Modified: 05 Dec 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.