DSA-2024-484: Security Update for Dell PowerFlex Appliance Multiple Third-Party Component Vulnerabilities
Summary: Dell PowerFlex Appliance remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
| Third-party Component | CVEs | More Information |
| Dell PowerEdge Server BIOS | CVE-2023-45745, CVE-2023-47855, CVE-2023-31355, CVE-2024-21978, CVE-2024-21980, CVE-2023-31315, CVE-2023-49141, CVE-2021-26344, CVE-2021-26387, CVE-2021-46772, CVE-2021-46746, CVE-2023-20518, CVE-2023-20578, CVE-2023-20584, CVE-2023-20591, CVE-2023-31356, CVE-2024-21981, CVE-2024-21801, CVE-2024-22374 | DSA-2024-160, DSA-2024-306, DSA-2024-344, DSA-2024-160, DSA-2024-350, DSA-2024-359 |
| iDRAC | CVE-2024-25943, CVE-2023-48795, CVE-2024-38433, CVE-2024-6387, CVE-2023-29499 | DSA-2024-099, DSA-2024-021, DSA-2024-223, DSA-2024-342, DSA-2024-286 |
| VMWare | CVE-2024-22273, CVE-2024-22274, CVE-2024-22275, CVE-2024-37086, CVE-2024-37087, CVE-2024-37085, CVE-2024-38812, CVE-2024-38813 | VMSA-2024-0011 |
| CUPS | CVE-2024-47176, CVE-2024-47076 | https://nvd.nist.gov/vuln/search |
| Python-cryptography | CVE-2023-50782 | https://nvd.nist.gov/vuln/search |
| libexpat | CVE-2023-52425 | https://nvd.nist.gov/vuln/search |
| openssl | CVE-2016-2183 | https://nvd.nist.gov/vuln/search |
| SQLParse | CVE-2023-20608 | https://nvd.nist.gov/vuln/search |
| OpenJDK | CVE-2024-21094 | https://nvd.nist.gov/vuln/search |
| JQuery | CVE-2020-11023 | https://nvd.nist.gov/vuln/search |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
PowerFlex appliance |
IC |
Versions prior to IC 46.376.00
|
Version IC 46.376.00 or later
|
|
|
PowerFlex appliance |
IC |
Versions prior to IC 46.381.00 |
Version IC 46.381.00 or laer |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
PowerFlex appliance |
IC |
Versions prior to IC 46.376.00
|
Version IC 46.376.00 or later
|
|
|
PowerFlex appliance |
IC |
Versions prior to IC 46.381.00 |
Version IC 46.381.00 or laer |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2024-12-12 |
Initial Release |
|
2.0 |
2025-02-20 |
Major update; remediation content: |
|
3.0 |
2025-03-24 |
MAjor update, remediation content: CVE-2020-11023 added as remediated since the initial release, |