Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000219782


DSA-2023-427: Security Update for Dell PowerProtect Agent for File System Vulnerabilities

Summary: Dell PowerProtect Agent for File System remediation is available for ddfscon with FSAgent that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

Medium

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String

CVE-2023-43081
PowerProtect Agent for File System Version 19.14 and prior, contains an incorrect default permissions vulnerability in ddfscon component. A low Privileged local attacker could potentially exploit this vulnerability, leading to overwriting of log files. 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String

CVE-2023-43081
PowerProtect Agent for File System Version 19.14 and prior, contains an incorrect default permissions vulnerability in ddfscon component. A low Privileged local attacker could potentially exploit this vulnerability, leading to overwriting of log files. 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed Product Software/Firmware
 
Affected Versions Remediated Versions Link
CVE-2023-43081 PowerProtect Agent for File System  Software Versions prior to 19.14 Version 19.15 https://www.dell.com/support/home/product-support/product/enterprise-copy-data-management/drivers

 
CVEs Addressed Product Software/Firmware
 
Affected Versions Remediated Versions Link
CVE-2023-43081 PowerProtect Agent for File System  Software Versions prior to 19.14 Version 19.15 https://www.dell.com/support/home/product-support/product/enterprise-copy-data-management/drivers

 

Revision History

RevisionDateDescription
1.02023-11-22Initial Release

Related Information


Article Properties


Affected Product

PowerProtect Data Manager, Product Security Information

Last Published Date

22 Nov 2023

Version

1

Article Type

Dell Security Advisory