DSA-2026-165: Security Update for Dell AppSync Vulnerabilities.

Yhteenveto: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Tämä artikkeli koskee tuotetta Tämä artikkeli ei koske tuotetta Tämä artikkeli ei liity tiettyyn tuotteeseen. Tässä artikkelissa ei yksilöidä kaikkia tuoteversioita.

Vaikutus

High

Tiedot

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-27110 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28257 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28258 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-27110 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28257 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28258 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies suosittelee, että kaikki asiakkaat ottavat huomioon sekä CVSS-peruspistemäärän että kaikki asiaankuuluvat väliaikaiset ja ympäristöön liittyvät pisteet, jotka voivat vaikuttaa tietyn tietoturvahaavoittuvuuden mahdolliseen vakavuuteen.

Tuotteet, joihin asia vaikuttaa, ja tilanteen korjaaminen

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2026-27110, CVE-2026-28257, CVE-2026-28258 Dell AppSync 4.6.0.4, 4.6.1.0 4.6.1.1 https://www.dell.com/support/product-details/en-us/product/appsync/drivers
CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2026-27110, CVE-2026-28257, CVE-2026-28258 Dell AppSync 4.6.0.4, 4.6.1.0 4.6.1.1 https://www.dell.com/support/product-details/en-us/product/appsync/drivers

Kiertotavat ja lievennyskeinot

n/a

Versiohistoria

Revision

Date

Description

1.0

2026-08-24

Initial Release

 

Kiitokset

Dell would like to thank brocked200 for reporting this issue.

Asiaan liittyvät tiedot

Tuotteet, joihin vaikutus kohdistuu

AppSync
Artikkelin ominaisuudet
Artikkelin numero: 000502484
Artikkelin tyyppi: Dell Security Advisory
Viimeksi muutettu: 24 elok. 2026
Etsi vastauksia kysymyksiisi muilta Dell-käyttäjiltä
Tukipalvelut
Tarkista, kuuluuko laitteesi tukipalveluiden piiriin.