DSA-2024-478 : Security Update for Dell NetWorker Vulnerabilities
Summary: Dell NetWorker remediation is available for NetWorker client vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2024-42422 |
Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
8.3 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2024-42422 |
Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
8.3 |
Affected Products & Remediation
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2024-42422 |
Dell NetWorker |
Dell NetWorker Client |
Versions 19.11 through 19.11.0.2 |
Version 19.11.0.3 or later |
https://www.dell.com/support/home/product-support/product/networker/drivers |
|
CVE-2024-42422 |
Dell NetWorker |
Dell NetWorker Client |
Versions prior to 19.10.0.6 |
Version 19.11.0.3, 19.10.0.6 or later |
https://www.dell.com/support/home/product-support/product/networker/drivers |
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2024-42422 |
Dell NetWorker |
Dell NetWorker Client |
Versions 19.11 through 19.11.0.2 |
Version 19.11.0.3 or later |
https://www.dell.com/support/home/product-support/product/networker/drivers |
|
CVE-2024-42422 |
Dell NetWorker |
Dell NetWorker Client |
Versions prior to 19.10.0.6 |
Version 19.11.0.3, 19.10.0.6 or later |
https://www.dell.com/support/home/product-support/product/networker/drivers |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
- Platforms: Windows & Linux (All variants and flavors are impacted)
- Versions prior to 19.10.0.6 mean versions 19.10.0.5 , 19.10.x, 19.9.x, 19.8.x, 19.7.x, 19.6.x, 19.5.x family of releases that are still under standard support. For more information on Dell End-of-Life Documents for converged infrastructure, midrange and enterprise storage, and storage networking products kindly refer to: https://www.dell.com/support/kbdoc/000185734/all-dell-emc-end-of-life-documents?lang=en
- Unless specified as impacted, the term “later releases” encompasses all NetWorker releases, under standard support, that are of a higher minor or major version than the specified release.
- Dell advises that you consistently upgrade to the latest release/version for your product
- The security advisory has been updated in light of the release of Version 19.11.0.3, customers have the option to upgrade to any of the versions/releases specified in the "Affected Products and Remediation" section
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2024-12-03 |
Initial Release |
|
2.0 |
2024-01-28 |
The security advisory has been updated in light of the release of Version 19.11.0.3 |