DSA-2022-156: Dell SmartFabric Storage Software Security Update for Multiple Component Vulnerabilities
Résumé: Dell SmartFabric Storage Software remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
High
Détails
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-31232 | SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access and perform actions on the affected system. | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-31232 | SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access and perform actions on the affected system. | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Produits concernés et mesure corrective
| CVEs Addressed | Product | Affected Version | Updated Version | Link to Update |
| CVE-2022-31232 | SmartFabric Storage Software | 1.0.0 | 1.1.0 | https://www.dell.com/support/home/product-support/product/dell-emc-smartfabric-storage-software-trial/drivers |
| CVEs Addressed | Product | Affected Version | Updated Version | Link to Update |
| CVE-2022-31232 | SmartFabric Storage Software | 1.0.0 | 1.1.0 | https://www.dell.com/support/home/product-support/product/dell-emc-smartfabric-storage-software-trial/drivers |
Solutions de contournement et mesures d’atténuation
If RADIUS and TACACS authentication is not a requirement, then customers can run the "rm /etc/ham/libnss_sac.enable" command to mitigate the vulnerability. If RADIUS and TACACS are a requirement, then customers must update.
Historique des révisions
| Revision | Date | Description |
| 1.0 | 2022-07-19 | Initial Release |
Informations connexes
Mention légale
Produits concernés
SmartFabric OS10 SoftwareProduits
Product Security InformationPropriétés de l’article
Numéro d’article: 000201667
Type d’article: Dell Security Advisory
Dernière modification: 18 Sep 2025
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.