DSA-2026-401: Security update for Dell ECS and ObjectScale Multiple Third Party Component Vulnerabilities

Yhteenveto: Dell ECS and ObjectScale remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Tämä artikkeli koskee tuotetta Tämä artikkeli ei koske tuotetta Tämä artikkeli ei liity tiettyyn tuotteeseen. Tässä artikkelissa ei yksilöidä kaikkia tuoteversioita.

Vaikutus

Critical

Tiedot

Third-party Component CVEs More Information
BusyBox CVE-2021-42374, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,;CVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2022-28391, CVE-2022-48174, CVE-2025-46394, CVE-2025-60876 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Dell iDRAC CVE-2024-25943, CVE-2025-22396, CVE-2026-26945,CVE-2026-26948 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
EDK2 CVE-2024-38796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GLib CVE-2024-52533 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
GNU C Library (glibc) CVE-2024-2961 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel Processor/Microcode CVE-2025-31648 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Intel TDX Module CVE-2025-22885, CVE-2025-27572,;CVE-2025-27940, CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
libexpat (Expat) CVE-2023-52340, CVE-2023-6780, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50602 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Linux Kernel CVE-2024-42154 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Nuvoton NPCT7xx TPM CVE-2026-6923 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSH CVE-2023-48795, CVE-2024-6387, CVE-2025-26466  https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSL CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
REDownloader CVE-2026-23855 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
Sqlite3 CVE-2025-29088 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies suosittelee, että kaikki asiakkaat ottavat huomioon sekä CVSS-peruspistemäärän että kaikki asiaankuuluvat väliaikaiset ja ympäristöön liittyvät pisteet, jotka voivat vaikuttaa tietyn tietoturvahaavoittuvuuden mahdolliseen vakavuuteen.

Tuotteet, joihin asia vaikuttaa, ja tilanteen korjaaminen

Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.7 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401
ObjectScale Versions prior to 4.3 with ECS Firmware Catalog versions prior to 2.6.3 Version 4.2.0.2 and 4.3.0.0 later with ECS Firmware Catalog 2.6.3 or later Open a Service Request for an Operating Environment Upgrade and Quote DSA-2026-401

Note: 

  1. Dell recommends all customers have their ObjectScale systems upgraded at the earliest opportunity by opening an “Operating Environment Upgrade” Service Request. 
  2. Please visit the Security Update Release Schedule for Supported Versions of ObjectScale (formerly ECS) for more information.

Versiohistoria

RevisionDateDescription
1.0 2026-09-03Initial Release

Asiaan liittyvät tiedot

Tuotteet, joihin vaikutus kohdistuu

ECS, ObjectScale, ECS Appliance, ECS Appliance Hardware Series, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, ObjectScale Software with Encryption, ObjectScale Software without Encryption , ObjectScale Appliance Series, ObjectScale Software Series ...
Artikkelin ominaisuudet
Artikkelin numero: 000509706
Artikkelin tyyppi: Dell Security Advisory
Viimeksi muutettu: 16 syysk. 2026
Etsi vastauksia kysymyksiisi muilta Dell-käyttäjiltä
Tukipalvelut
Tarkista, kuuluuko laitteesi tukipalveluiden piiriin.