DSA-2025-025: Security Update for Dell VxRail for Multiple Vulnerabilities

Resumen: Dell VxRail remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Impacto

Critical

Detalles

Third-party Component

CVEs

More Information

Updates for OSS software - idna, certifi, urllib3

CVE-2022-23491, CVE-2023-37920, CVE-2023-43804, CVE-2023-45803, CVE-2024-3651

See NVD link below for individual scores for each CVE. 

https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

SuSE Updates

CVE-2024-9287,CVE-2023-50782,CVE-2024-28168,CVE-2024-9681,CVE-2024-21208,CVE-2024-21210,CVE-2024-21217,CVE-2024-21235,CVE-2024-43398,CVE-2024-41123,CVE-2024-41946,CVE-2024-35176,CVE-2024-39908,CVE-2024-10976,CVE-2024-10977,CVE-2024-10978,CVE-2024-10979,CVE-2023-5388,CVE-2024-52533,CVE-2024-43854,CVE-2024-49925,CVE-2024-49945,CVE-2024-50208,CVE-2022-48879,CVE-2022-48956,CVE-2022-48959,CVE-2022-48960,CVE-2022-48962,CVE-2022-48991,CVE-2022-49015,CVE-2024-45013,CVE-2024-45016,CVE-2024-45026,CVE-2024-46716,CVE-2024-46813,CVE-2024-46814,CVE-2024-46815,CVE-2024-46816,CVE-2024-46817,CVE-2024-46818,CVE-2024-46849,CVE-2024-47668,CVE-2024-47674,CVE-2024-47684,CVE-2024-47706,CVE-2024-47747,CVE-2024-47748,CVE-2024-49860,CVE-2024-49930,CVE-2024-49936,CVE-2024-49960,CVE-2024-49969,CVE-2024-49974,CVE-2024-49991,CVE-2024-49995,CVE-2024-50047,CVE-2024-52316

SUSE.comThis hyperlink is taking you to a website outside of Dell Technologies.

Security Update for Dell iDRAC Service Module 7-Zip Vulnerability

CVE-2023-31102,CVE-2023-40481

DSA-2024-379

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2025-21111

Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

7.5

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2025-21111

Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

7.5

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recomienda que todos los clientes tengan en cuenta tanto la puntuación base como cualquier otra puntuación ambiental y temporal relevante que pueda afectar la posible gravedad asociada con la vulnerabilidad de seguridad en particular.

Corrección y productos afectados

Product

Affected Versions

Remediated Versions

Link

Dell VxRail Appliance

Versions 8.0.000 through 8.0.311

Version 8.320 or later

Drivers & Downloads

Product

Affected Versions

Remediated Versions

Link

Dell VxRail Appliance

Versions 8.0.000 through 8.0.311

Version 8.320 or later

Drivers & Downloads

Historial de revisiones

Revision

Date

Description

1.0

2025-01-08

Initial Release

2.0

2025-01-16

Updated the advisory to extend our gratitude to Klaas Demter for reporting this issue.

3.0

2025-01-20

Updated the advisory by Adding Third Party Security Update from Dell iDRAC for CVE-2023-31102, CVE-2023-40481

Reconocimientos

Dell Technologies would like to thank Klaas Demter for reporting this issue.

Información relacionada

Productos afectados

VxRail, VMware, VxRail Appliance Series
Propiedades del artículo
Número del artículo: 000269958
Tipo de artículo: Dell Security Advisory
Última modificación: 08 sept 2025
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.