DSA-2023-109: Dell ECS security update for Multiple vulnerabilities.
Resumen: Dell ECS 3.8.0.2 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a:
Este artículo no se aplica a:
Este artículo no está vinculado a ningún producto específico.
En este artículo no se identifican todas las versiones de los productos.
Impacto
High
Detalles
| Proprietary Code CVEs | Description | CVSS Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25934 | DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request. | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
| Proprietary Code CVEs | Description | CVSS Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25934 | DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request. | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Productos afectados y corrección
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell ECS | Versions prior to 3.8.0.2 | Version 3.8.0.2 | Dell recommends all customers have their ECS systems upgraded at the earliest opportunity by opening a “Operating Environment Upgrade” Service Request. |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell ECS | Versions prior to 3.8.0.2 | Version 3.8.0.2 | Dell recommends all customers have their ECS systems upgraded at the earliest opportunity by opening a “Operating Environment Upgrade” Service Request. |
Soluciones alternativas y mitigaciones
None.
Historial de revisiones
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-05-02 | Initial Release |
| 2.0 | 2023-05-08 | Updated Affect Products section under Article Properties |
| 3.0 | 2023-09-01 | Updated for enhanced presentation with no changes to content. Added link to CVSS calculator. |
Información relacionada
Aviso legal
Productos afectados
ECS, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, ECS SoftwarePropiedades del artículo
Número de artículo: 000212970
Tipo de artículo: Dell Security Advisory
Última modificación: 01 sept 2023
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.