DSA-2024-420: Security Update for Dell EMC AppSync for Multiple Vulnerabilities
Summary: Dell EMC AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Medium
Details
|
Third-party Component |
CVEs |
More Information |
|
python-cryptography package |
CVE-2023-50782 |
|
|
libexpat |
CVE-2023-52425 |
|
Proprietary Code CVE |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2024-39586 |
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure. |
2.9 |
|
Proprietary Code CVE |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2024-39586 |
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure. |
2.9 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell EMC AppSync |
Versions 4.3.0.0 through 4.6.0.0 |
Version 4.6.0.3 |
https://www.dell.com/support/home/product-support/product/appsync/drivers |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell EMC AppSync |
Versions 4.3.0.0 through 4.6.0.0 |
Version 4.6.0.3 |
https://www.dell.com/support/home/product-support/product/appsync/drivers |
Affected version includes all Service Pack releases. Remediation version is the patch release.
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2024-10-09 |
Initial Release |
|
2.0 |
2024-10-25 |
Updated for enhanced presentation with no changes to content |
Acknowledgements
CVE-2024-39586: Dell would like to thank B4gpipe for reporting this issue.