DSA-2022-064: Dell EMC CloudLink Security Update for Security Vulnerabilities
Résumé: Dell EMC CloudLink remediation is available for security vulnerabilities that may potentially be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
High
Détails
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24414 | Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. Tokens should not be used in request URL to avoid such attacks. | 7.6 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24414 | Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. Tokens should not be used in request URL to avoid such attacks. | 7.6 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Produits concernés et mesure corrective
| Product | Affected Versions | Updated Versions | Link to Update | |
| Dell EMC CloudLink | Versions before 7.1.3 | 7.1.3 | https://www.dell.com/support/home/en-us/product-support/product/cloudlink-securevm/drivers | |
| Product | Affected Versions | Updated Versions | Link to Update | |
| Dell EMC CloudLink | Versions before 7.1.3 | 7.1.3 | https://www.dell.com/support/home/en-us/product-support/product/cloudlink-securevm/drivers | |
Historique des révisions
| Revision | Date | Description |
| 1.0 | 2022-03-16 | Initial Release |
Informations connexes
Mention légale
Produits concernés
CloudLinkProduits
Product Security InformationPropriétés de l’article
Numéro d’article: 000197425
Type d’article: Dell Security Advisory
Dernière modification: 18 sept. 2025
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.