DSA-2024-246: Security Update for Dell PowerFlex Appliance Multiple Third-Party Component Vulnerabilities

Resumen: Dell PowerFlex Appliance remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Impacto

High

Detalles adicionales

In the case of manual upgrade for PowerFlex appliance, please see this link: https://www.dell.com/support/home/product-support/product/powerflex-appliance-int-ca-sw/drivers

Detalles

Third-party Component CVEs More Information
Dell PowerEdge Server BIOS CVE-2024-0162, CVE-2024-0163, CVE-2024-0154, CVE-2024-0173, CVE-2023-31346, CVE-2023-31347, CVE-2024-0161 DSA-2024-004
DSA-2024-003
DSA-2024-034
DSA-2024-002
DSA-2024-006
Intel CVE-2023-32666, CVE-2023-38575, CVE-2023-39368, CVE-2023-22655, CVE-2023-35191, CVE-2024-21828 DSA-2024-005
DSA-2024-206
 
VMware CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255, CVE-2024-22274, CVE-2024-22275, CVE-2024-37087, CVE-2024-37079, CVE-2024-37080, CVE-2024-37081
 
VMSA-2024-0006 This hyperlink is taking you to a website outside of Dell Technologies.
VMSA-2024-0011 This hyperlink is taking you to a website outside of Dell Technologies.
VMSA-2024-0013 This hyperlink is taking you to a website outside of Dell Technologies.
VMSA-2024-0012 This hyperlink is taking you to a website outside of Dell Technologies.   
iDRAC CVE-2023-29499 DSA-2024-286

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2025-30481 Dell Management VM, version(s) prior to 4.6.0, contain(s) deprecated cryptographic settings. An adjacent unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack. 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.  
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2025-30481 Dell Management VM, version(s) prior to 4.6.0, contain(s) deprecated cryptographic settings. An adjacent unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack. 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.  
Dell Technologies recomienda que todos los clientes tengan en cuenta tanto la puntuación base como cualquier otra puntuación ambiental y temporal relevante que pueda afectar la posible gravedad asociada con la vulnerabilidad de seguridad en particular.

Corrección y productos afectados

Product Software/Firmware Affected Versions Remediated Versions Link
PowerFlex Appliance Intelligent Catalogue (IC) Versions prior to IC-46.375.01 Version IC-46.375.01 IC release
Product Software/Firmware Affected Versions Remediated Versions Link
PowerFlex Appliance Intelligent Catalogue (IC) Versions prior to IC-46.375.01 Version IC-46.375.01 IC release

Historial de revisiones

RevisionDateDescription
1.02024-06-11Initial Release
2.02024-07-22Added VMware and iDRAC CVE
3.02025-11-24Added details for CVE-2025-30481

 

Información relacionada

Productos afectados

PowerFlex Appliance, PowerFlex appliance connectivity, PowerFlex appliance Intelligent Catalog Software, PowerFlex appliance R650, PowerFlex appliance R6525, PowerFlex appliance R660, PowerFlex appliance R6625, Powerflex appliance R750 , PowerFlex appliance R760, PowerFlex appliance R7625, Product Security Information, PowerFlex appliance R640, PowerFlex appliance R740XD, PowerFlex appliance R7525, PowerFlex appliance R840 ...
Propiedades del artículo
Número del artículo: 000225977
Tipo de artículo: Dell Security Advisory
Última modificación: 24 nov 2025
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.