DSA-2022-087: Dell EMC PowerFlex Custom Node 15G, VxFlex Ready Node 14G, and ScaleIO Ready Node 13G Security Update for Multiple Vulnerabilities

Résumé: Remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Impact

High

Détails

Component CVEs More Information
Intel CVE-2021-0060, CVE-2021-0147 Intel article: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00470.html
CVE-2021-0103, CVE-2021-0114,
CVE-2021-0115, CVE-2021-0116,
CVE-2021-0117, CVE-2021-0118,
CVE-2021-0111, CVE-2021-0107, CVE-2021-0125, CVE-2021-0124, CVE-2021-0119, CVE-2021-0091, CVE-2021-0092, CVE-2021-0093
Intel article: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00527.html
CVE-2021-0127 Intel article: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00532.html
VMware ESXi CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050 VMware article:
https://www.vmware.com/security/advisories/VMSA-2022-0004.html
Dell PowerEdge Server BIOS CVE-2019-14584, CVE-2021-28210, CVE-2021-28211 Dell article: https://www.dell.com/support/kbdoc/en-ie/000198065/dsa-2022-088
DELL iDRAC CVE-2022-24442 https://blog.jetbrains.com/
Component CVEs More Information
Intel CVE-2021-0060, CVE-2021-0147 Intel article: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00470.html
CVE-2021-0103, CVE-2021-0114,
CVE-2021-0115, CVE-2021-0116,
CVE-2021-0117, CVE-2021-0118,
CVE-2021-0111, CVE-2021-0107, CVE-2021-0125, CVE-2021-0124, CVE-2021-0119, CVE-2021-0091, CVE-2021-0092, CVE-2021-0093
Intel article: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00527.html
CVE-2021-0127 Intel article: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00532.html
VMware ESXi CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050 VMware article:
https://www.vmware.com/security/advisories/VMSA-2022-0004.html
Dell PowerEdge Server BIOS CVE-2019-14584, CVE-2021-28210, CVE-2021-28211 Dell article: https://www.dell.com/support/kbdoc/en-ie/000198065/dsa-2022-088
DELL iDRAC CVE-2022-24442 https://blog.jetbrains.com/
Dell Technologies recommande à tous les clients de prendre en compte à la fois le score de base CVSS et les scores temporels et environnementaux pertinents qui peuvent avoir un impact sur la gravité potentielle associée à une faille de sécurité donnée.

Produits concernés et mesure corrective

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2019-14584 CVE-2021-28210 CVE-2021-28211 R650, R750, R6525 custom node
 
BIOS Versions before 1.5.4 for Intel and 2.6.6 for AMD
 
Intel BIOS: 1.5.4
AMD BIOS: 2.6.6
Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
 
CVE-2021-0060, CVE-2021-0147, CVE-2021-0103, CVE-2021-0114, CVE-2021-0115, CVE-2021-0116, CVE-2021-0117, CVE-2021-0118, CVE-2021-0099, CVE-2021-0111, CVE-2021-0107, CVE-2021-0125, CVE-2021-0124, CVE-2021-0119, CVE-2021-0092, CVE-2021-0091, CVE-2021-0093, CVE-2021-0127, CVE-2019-14584, CVE-2021-28210 CVE-2021-28211 R640, R740, and R840 custom node BIOS versions before 2.13.3 2.13.3 Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
CVE-2022-24442 R650, R750 custom node
 
iDRAC versions prior to 5.10.10.00 5.10.10.00 Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
CVE-2022-24442 R640, R740, R840 custom node iDRAC versions prior to 5.10.10.00 5.10.10.00 Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050 ESXi 7.0 patches Versions before 7.0U3c 7.0U3c Refer to Updated Firmware and Driver Support Matrix listing supported ESXi versions per Product offering and link guidance.
CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2019-14584 CVE-2021-28210 CVE-2021-28211 R650, R750, R6525 custom node
 
BIOS Versions before 1.5.4 for Intel and 2.6.6 for AMD
 
Intel BIOS: 1.5.4
AMD BIOS: 2.6.6
Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
 
CVE-2021-0060, CVE-2021-0147, CVE-2021-0103, CVE-2021-0114, CVE-2021-0115, CVE-2021-0116, CVE-2021-0117, CVE-2021-0118, CVE-2021-0099, CVE-2021-0111, CVE-2021-0107, CVE-2021-0125, CVE-2021-0124, CVE-2021-0119, CVE-2021-0092, CVE-2021-0091, CVE-2021-0093, CVE-2021-0127, CVE-2019-14584, CVE-2021-28210 CVE-2021-28211 R640, R740, and R840 custom node BIOS versions before 2.13.3 2.13.3 Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
CVE-2022-24442 R650, R750 custom node
 
iDRAC versions prior to 5.10.10.00 5.10.10.00 Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
CVE-2022-24442 R640, R740, R840 custom node iDRAC versions prior to 5.10.10.00 5.10.10.00 Downloads (in case of upgrade using OME)
Documents (in case of manual upgrade)
CVE-2021-22040, CVE-2021-22041, CVE-2021-22042, CVE-2021-22043, CVE-2021-22050 ESXi 7.0 patches Versions before 7.0U3c 7.0U3c Refer to Updated Firmware and Driver Support Matrix listing supported ESXi versions per Product offering and link guidance.

Historique des révisions

RevisionDateDescription
1.02022-03-29Initial release
2.02022-04-22Updated Details Section
3.02022-05-11Updated section with CVE changes

Informations connexes

Produits concernés

VxFlex Ready Nodes, PowerFlex custom node, PowerFlex custom node, PowerFlex custom node R650, PowerFlex custom node R750, Product Security Information, VxFlex Ready Node, ScaleIO Ready Node-PowerEdge 13G, VxFlex Ready Node R640
Propriétés de l’article
Numéro d’article: 000198136
Type d’article: Dell Security Advisory
Dernière modification: 18 Sep 2025
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.