Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000219487


DSA-2023-402: Security Update for Dell EMC Enterprise SONiC Distribution Multiple Third-Party Component Vulnerabilities.

Summary: Dell EMC Enterprise SONiC remediation is available for multiple Third-party vulnerabilities.

Article Content


Impact

High

Details

Third-party Component CVEs More Information
c-ares CVE-2023-31130, CVE-2023-32067
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
cpio CVE-2019-14866, CVE-2021-38185
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libfastjson CVE-2020-12762
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libssh2 CVE-2019-13115, CVE-2019-17498, CVE-2020-22218
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libx11 CVE-2023-3138
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
libxpm CVE-2022-4883, CVE-2022-44617, CVE-2022-46285
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
openssh CVE-2023-38408
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
openssl CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-2650, CVE-2023-3446, CVE-2023-3817
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
Python2.7 CVE-2021-23336, CVE-2022-0391, CVE-2022-48560, CVE-2022-48565, CVE-2022-48566, CVE-2023-24329, CVE-2023-40217
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
Python3.7 CVE-2015-20107, CVE-2020-10735, CVE-2021-3426, CVE-2021-3733, CVE-2021-3737, CVE-2021-4189, CVE-2022-45061
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
systemd CVE-2022-3821
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 
vim CVE-2022-4141, CVE-2023-0054, CVE-2023-1175, CVE-2023-2610
See NVD link below for individual scores for each CVE. 
https://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Remediated Versions Link
Dell EMC Enterprise SONiC Distribution Versions prior to 4.1.2  4.1.2  Enterprise SONiC OS 4.1.2 gns3
Product Affected Versions Remediated Versions Link
Dell EMC Enterprise SONiC Distribution Versions prior to 4.1.2  4.1.2  Enterprise SONiC OS 4.1.2 gns3

Revision History

RevisionDateDescription
1.02023-11-13Initial Release
2.02023-12-05Formatting change with no content changes

Related Information


Article Properties


Affected Product

Enterprise SONiC Distribution

Last Published Date

05 Dec 2023

Version

2

Article Type

Dell Security Advisory