在 Dell Data Protection Virtual Edition 中发布“Shell 冲击漏洞”

Résumé: 本文提供有关 Shell shock Bash Bug CVE-2014-6271 安全漏洞及其如何影响 Dell Data Protection |Virtual Edition 软件。

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Symptômes

受影响的产品:

  • Dell Data Protection | Virtual Edition

受影响的版本:

  • v9.2 及更低版本

通过从 bash shell 提示符处运行以下命令来测试此漏洞:

env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

如果在输出中显示单词 vulnerable ,则计算机容易受到该漏洞的攻击。

即使存在漏洞,攻击者也必须能够访问 VE 服务器上的特定端口才能利用该漏洞。

最佳实践是 Dell Data Protection |Virtual Edition 服务器不面向互联网,而是使用代理服务来满足面向互联网的要求。

如果 Dell Data Protection |Virtual Edition 不面向互联网,因此无法在组织外部利用 ShellShock 问题。

Cause

较旧版本的 Dell Data Protection |Virtual Edition 容易受到 Ubuntu 安全通知 USN-2362-1 中所述的 bash shell 中的漏洞影响,通常称为 Shell 撞击漏洞

问题参数:

  • Dell Data Protection |Virtual Edition 控制台和 SSH 服务器使用 bash shell,可利用该 shell 将尾随代码传递到 bash shell 并获得对命令环境的未经授权的访问权限。
  • Dell Data Protection |加密预启动身份验证 (PBA) 软件,例如自加密驱动器 (SED) 管理或用于验证客户端的硬件加密加速器 (HCA)。

Résolution

此问题已在 Dell Data Protection |Virtual Edition v9.3 及更高版本。

要纠正此问题:

  1. 打开 Virtual Edition 远程桌面控制台。
  2. 从主菜单中选择 Launch Shell选项,然后执行以下步骤:
  3. 键入命令: su ddpsupport
  4. 按<Enter>键。
  5. 出现提示时,输入为 ddpsupport 用户身份登录。
  6. 有一个更新提示,开头为 ddpsupport@
  7. 键入命令: sudo apt-get update
    • 此命令使用互联网联系 Ubuntu 更新服务器,并请求所需的相关更新。
  8. 键入命令: sudo apt-get install bash

更新完成后,通过再次测试确认更新解决了漏洞。

注意: 命令的输出中没有“ 易受攻击” 一词: env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

Informations supplémentaires

更多参考资料

CVE-2014-6271 此超链接会将您带往 Dell Technologies 之外的网站。 在 NIST 网站上

Produits concernés

Dell Encryption
Propriétés de l’article
Numéro d’article: 000129498
Type d’article: Solution
Dernière modification: 26 août 2026
Version:  10
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.