DSA-2024-078: Security Update for Dell ECS access control Vulnerability.
Resumen: Dell ECS remediation is available for access control vulnerability that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a:
Este artículo no se aplica a:
Este artículo no está vinculado a ningún producto específico.
En este artículo no se identifican todas las versiones de los productos.
Impacto
Medium
Detalles
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-22459 | Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace. | 6.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-22459 | Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to all buckets and their data within a namespace. | 6.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Productos afectados y corrección
| CVEs Addressed | Product | Affected Version(s) | Remediated Versions | Link to Update |
|---|---|---|---|---|
| CVE-2024-22459 | Dell ECS | Versions 3.8 through 3.8.0.4 | ECS 3.8.0.5 |
https://www.dell.com/support/incidents-online |
| CVE-2024-22459 | Dell ECS | Version 3.7 through 3.7.0.6 | ECS 3.7.0.7 |
https://www.dell.com/support/incidents-online |
| CVE-2024-22459 | Dell ECS | Versions 3.6 through 3.6.2.5 | ECS 3.6.2.6 | https://www.dell.com/support/incidents-online |
| CVEs Addressed | Product | Affected Version(s) | Remediated Versions | Link to Update |
|---|---|---|---|---|
| CVE-2024-22459 | Dell ECS | Versions 3.8 through 3.8.0.4 | ECS 3.8.0.5 |
https://www.dell.com/support/incidents-online |
| CVE-2024-22459 | Dell ECS | Version 3.7 through 3.7.0.6 | ECS 3.7.0.7 |
https://www.dell.com/support/incidents-online |
| CVE-2024-22459 | Dell ECS | Versions 3.6 through 3.6.2.5 | ECS 3.6.2.6 | https://www.dell.com/support/incidents-online |
Dell recommends all customers have their ECS systems upgraded at the earliest opportunity by opening a “Operating Environment Upgrade” Service Request.
Soluciones alternativas y mitigaciones
None
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2024-02-26 | Initial Release |
Agradecimientos
Dell Technologies would like to thank Amund Tenstad for reporting this issue.
Información relacionada
Aviso legal
Productos afectados
ECS, ECS Appliance Software with Encryption, ECS Appliance Software without EncryptionPropiedades del artículo
Número de artículo: 000222470
Tipo de artículo: Dell Security Advisory
Última modificación: 26 feb 2024
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.