DSA-2024-477: Security Update for Dell NetWorker Runtime Environment (NRE) Multiple Component Vulnerabilities

Summary: Dell NetWorker Runtime Environment (NRE) remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.

Ez a cikk a következő(k)re vonatkozik: Ez a cikk nem vonatkozik a következő(k)re: Ez a cikk nem kapcsolódik egyetlen konkrét termékhez sem. Ez a cikk nem azonosítja az összes termékverziót.

Impact

High

Details

Third-party Component

CVEs

More Information

Java SE Embedded

CVE-2023-42950, CVE-2024-25062, CVE-2024-21235, CVE-2024-21210, CVE-2024-21208, CVE-2024-21217

See NVD link below for individual scores for each CVE.

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-47476

Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution.

7.8

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-47476

Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution.

7.8

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Érintett termékek és helyreállítás

CVEs Addressed

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

CVE-2023-42950, CVE-2024-25062, CVE-2024-21235, CVE-2024-21210, CVE-2024-21208, CVE-2024-21217

Dell NetWorker Runtime Environment (NRE)

NetWorker Runtime Environment (NRE)

Version NRE 8.0.22

Version NRE 8.0.23 or later

https://www.dell.com/support/home/product-support/product/networker/drivers

CVE-2024-47476

Dell NetWorker Runtime Environment (NRE)

NetWorker Management Console

Version NRE 8.0.22

Version NRE 8.0.23 or later

https://www.dell.com/support/home/product-support/product/networker/drivers

CVEs Addressed

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

CVE-2023-42950, CVE-2024-25062, CVE-2024-21235, CVE-2024-21210, CVE-2024-21208, CVE-2024-21217

Dell NetWorker Runtime Environment (NRE)

NetWorker Runtime Environment (NRE)

Version NRE 8.0.22

Version NRE 8.0.23 or later

https://www.dell.com/support/home/product-support/product/networker/drivers

CVE-2024-47476

Dell NetWorker Runtime Environment (NRE)

NetWorker Management Console

Version NRE 8.0.22

Version NRE 8.0.23 or later

https://www.dell.com/support/home/product-support/product/networker/drivers

The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

  1. Platforms: Windows & Linux (All variants and flavors are impacted)
  2. Unless specified as impacted, the term “later releases” encompasses all NetWorker releases, under standard support, that are of a higher minor or major version than the specified release.
  3. Dell advises that you consistently upgrade to the most recent release/version of your product.

Revision History

Revision

Date

Description

1.0

2024-12-03

Initial Release

Related Information

Érintett termékek

NetWorker Family, NetWorker, NetWorker Management Console
Termék tulajdonságai
Article Number: 000255884
Article Type: Dell Security Advisory
Utoljára módosítva: 09 szept. 2025
Választ kaphat kérdéseire más Dell-felhasználóktól
Támogatási szolgáltatások
Ellenőrizze, hogy a készüléke rendelkezik-e támogatási szolgáltatással.