DSA-2024-246: Security Update for Dell PowerFlex Appliance Multiple Third-Party Component Vulnerabilities

Summary: Dell PowerFlex Appliance remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Additional Details

In the case of manual upgrade for PowerFlex appliance, please see this link: https://www.dell.com/support/home/product-support/product/powerflex-appliance-int-ca-sw/drivers

Details

Third-party Component CVEs More Information
Dell PowerEdge Server BIOS CVE-2024-0162, CVE-2024-0163, CVE-2024-0154, CVE-2024-0173, CVE-2023-31346, CVE-2023-31347, CVE-2024-0161 DSA-2024-004
DSA-2024-003
DSA-2024-034
DSA-2024-002
DSA-2024-006
Intel CVE-2023-32666, CVE-2023-38575, CVE-2023-39368, CVE-2023-22655, CVE-2023-35191, CVE-2024-21828 DSA-2024-005
DSA-2024-206
 
VMware CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255, CVE-2024-22274, CVE-2024-22275, CVE-2024-37087, CVE-2024-37079, CVE-2024-37080, CVE-2024-37081
 
VMSA-2024-0006 This hyperlink is taking you to a website outside of Dell Technologies.
VMSA-2024-0011 This hyperlink is taking you to a website outside of Dell Technologies.
VMSA-2024-0013 This hyperlink is taking you to a website outside of Dell Technologies.
VMSA-2024-0012 This hyperlink is taking you to a website outside of Dell Technologies.   
iDRAC CVE-2023-29499 DSA-2024-286

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2025-30481 Dell Management VM, version(s) prior to 4.6.0, contain(s) deprecated cryptographic settings. An adjacent unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack. 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.  
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2025-30481 Dell Management VM, version(s) prior to 4.6.0, contain(s) deprecated cryptographic settings. An adjacent unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack. 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.  
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Software/Firmware Affected Versions Remediated Versions Link
PowerFlex Appliance Intelligent Catalogue (IC) Versions prior to IC-46.375.01 Version IC-46.375.01 IC release
Product Software/Firmware Affected Versions Remediated Versions Link
PowerFlex Appliance Intelligent Catalogue (IC) Versions prior to IC-46.375.01 Version IC-46.375.01 IC release

Revision History

RevisionDateDescription
1.02024-06-11Initial Release
2.02024-07-22Added VMware and iDRAC CVE
3.02025-11-24Added details for CVE-2025-30481

 

Related Information

Affected Products

PowerFlex Appliance, PowerFlex appliance connectivity, PowerFlex appliance Intelligent Catalog Software, PowerFlex appliance R650, PowerFlex appliance R6525, PowerFlex appliance R660, PowerFlex appliance R6625, Powerflex appliance R750 , PowerFlex appliance R760, PowerFlex appliance R7625, Product Security Information, PowerFlex appliance R640, PowerFlex appliance R740XD, PowerFlex appliance R7525, PowerFlex appliance R840 ...
Article Properties
Article Number: 000225977
Article Type: Dell Security Advisory
Last Modified: 24 Nov 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.