DSA-2024-491: Security Update for Dell InsightIQ Multiple Security Vulnerabilities
Yhteenveto: Dell InsightIQ remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Vaikutus
Medium
Tiedot
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-53293 |
Dell InsightIQ version 5.1 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access. |
6.7 |
|
| CVE-2024-47979 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
5.6 |
|
| CVE-2024-53294 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
5.3 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-53293 |
Dell InsightIQ version 5.1 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access. |
6.7 |
|
| CVE-2024-47979 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
5.6 |
|
| CVE-2024-53294 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
5.3 |
Tuotteet, joihin asia vaikuttaa, ja tilanteen korjaaminen
| Product |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|
| PowerScale InsightIQ |
Versions 5.0.0 through 5.1.x |
Version 5.2.0 or later |
| Product |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|
| PowerScale InsightIQ |
Versions 5.0.0 through 5.1.x |
Version 5.2.0 or later |
Versiohistoria
| Revision | Date | Description |
|---|---|---|
|
1.0 | 2025-01-09 | Initial Release |
|
2.0 | 2025-01-09 |
Updated for enhanced presentation with no changes to content |