在 Dell Data Protection Virtual Edition 中抨擊「Shell Shock 漏洞」

Résumé: 本文提供 Shell shock Bash 漏洞 CVE-2014-6271 安全性漏洞的相關資訊,以及此漏洞如何影響 Dell Data Protection |虛擬版軟體。

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Symptômes

受影響的產品:

  • Dell Data Protection | Virtual Edition

受影響的版本:

  • v9.2 和更舊版本

從 bash shell 提示字元執行下列命令,以測試此漏洞:

env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

如果輸出中出現 「易受攻擊 」一詞,則計算機容易受到攻擊。

即使存在漏洞,攻擊者也必須能夠訪問 VE 伺服器上的特定埠才能使用該漏洞。

Dell Data Protection |Virtual Edition 伺服器並非面向網際網路,而是使用代理服務來滿足因特網需求。

如果 Dell Data Protection |Virtual Edition 不面向 Internet,ShellShock 問題無法在組織外部利用。

Cause

舊版 Dell Data Protection |Virtual Edition 容易受到 Ubuntu 安全性通知 USN-2362-1 中所述的 bash shell 漏洞攻擊,通常稱為 Shell Shock 漏洞

問題參數:

  • 戴爾數據保護 |Virtual Edition 主控台和 SSH 伺服器使用 bash shell,可透過將尾隨的程式碼傳遞到 bash shell 並未經授權存取命令環境來利用此漏洞。
  • Dell Data Protection |用於驗證用戶端的加密開機前驗證 (PBA) 軟體,例如自我加密磁碟機 (SED) 管理或硬體加密加速器 (HCA)。

Résolution

此問題已在 Dell Data Protection |Virtual Edition v9.3 及更新版本。

若要修正此問題:

  1. 開啟 Virtual Edition 遠端桌面主控台。
  2. 從主功能表中選擇 啟動 Shell 選項,然後按照下列步驟操作:
  3. 輸入命令: su ddpsupport
  4. 按下 Enter 鍵。
  5. 出現提示時,請輸入為 ddpsupport 使用者。
  6. 更新提示的開頭為 ddpsupport@
  7. 輸入命令: sudo apt-get update
    • 此命令會使用網際網路聯絡 Ubuntu 更新伺服器,並要求所需的相關更新。
  8. 輸入命令: sudo apt-get install bash

更新完成後,通過再次測試確認更新解決了漏洞。

注意: 命令輸出中不存在 「易受攻擊 」一詞: env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

Informations supplémentaires

更多參考資料

CVE-2014-6271 此超連結會帶您前往 Dell Technologies 以外的網站。 在 NIST 網站上

Produits concernés

Dell Encryption
Propriétés de l’article
Numéro d’article: 000129498
Type d’article: Solution
Dernière modification: 26 août 2026
Version:  10
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.