DSA-2023-283: Security Update for Dell SmartFabric Storage Software Vulnerabilities

Resumen: Dell SmartFabric Storage Software remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Este artículo se aplica a: Este artículo no se aplica a: Este artículo no está vinculado a ningún producto específico. En este artículo no se identifican todas las versiones de los productos.

Impacto

Critical

Detalles

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-32485 Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability affecting user authentication. Dell recommends customers to upgrade at the earliest opportunity. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-32485 Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability affecting user authentication. Dell recommends customers to upgrade at the earliest opportunity. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recomienda que todos los clientes tengan en cuenta la puntuación base CVSS y las puntuaciones temporales o de entorno relevantes que puedan afectar a la posible gravedad asociada a una determinada vulnerabilidad de seguridad.

Productos afectados y corrección

CVEs Addressed Product Affected Versions Remediated Versions Link
 CVE-2023-32485 Dell SmartFabric Storage Software Versions before 1.4.0  1.4.0  https://www.dell.com/support
CVEs Addressed Product Affected Versions Remediated Versions Link
 CVE-2023-32485 Dell SmartFabric Storage Software Versions before 1.4.0  1.4.0  https://www.dell.com/support

Soluciones alternativas y mitigaciones

none

Historial de revisiones

RevisionDateDescription
1.02023-08-08Initial Release
2.02023-10-05Major Revision: added relevant URL to the CVEand modified minor formatting without content change.

Información relacionada

Productos afectados

SmartFabric Storage Software for NVMe/TCP SAN, SmartFabric Storage Software Download for NVMe/TCP SAN
Propiedades del artículo
Número de artículo: 000216587
Tipo de artículo: Dell Security Advisory
Última modificación: 05 oct 2023
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.