DSA-2021-295: Dell EMC PowerStore Family Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-44832, and CVE-2022-23307)

Riepilogo: Dell EMC PowerStore Family remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

Critical

Dettagli

Third-party Component CVEs More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
CVE-2021-45046
CVE-2021-45105
CVE-2021-44832
CVE-2022-23307
Third-party Component CVEs More information
Apache log4j CVE-2021-44228 Apache Log4j Remote Code Execution
CVE-2021-45046
CVE-2021-45105
CVE-2021-44832
CVE-2022-23307
Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-44228 Dell EMC PowerStore Family Operating System
 
Versions before 2.0.1.3-1538564 PowerStore T OS Upgrade 2.0.1.3-1538564
PowerStore X OS Upgrade 2.0.1.3-1538564
PowerStore T OS Upgrade 2.1.0.0-1561821
https://www.dell.com/support/home/?app=drivers
CVE-2021-45046
CVE-2021-45105 Dell EMC PowerStore Family Operating System
 
Versions before 2.1.1.0-1649887 PowerStore T OS Upgrade 2.1.1.0-1649887
PowerStore X OS 2.1.1.0-1649887
 
https://www.dell.com/support/home/?app=drivers

See KB article 196367: DSA-2022-014: Dell EMC PowerStore Family Security Update for Multiple Vulnerabilities
CVE-2021-44832
CVE-2022-23307
CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-44228 Dell EMC PowerStore Family Operating System
 
Versions before 2.0.1.3-1538564 PowerStore T OS Upgrade 2.0.1.3-1538564
PowerStore X OS Upgrade 2.0.1.3-1538564
PowerStore T OS Upgrade 2.1.0.0-1561821
https://www.dell.com/support/home/?app=drivers
CVE-2021-45046
CVE-2021-45105 Dell EMC PowerStore Family Operating System
 
Versions before 2.1.1.0-1649887 PowerStore T OS Upgrade 2.1.1.0-1649887
PowerStore X OS 2.1.1.0-1649887
 
https://www.dell.com/support/home/?app=drivers

See KB article 196367: DSA-2022-014: Dell EMC PowerStore Family Security Update for Multiple Vulnerabilities
CVE-2021-44832
CVE-2022-23307

Cronologia delle revisioni

RevisionDateDescription
1.02021-12-30Initial Release
2.02022-01-26Updated Affected Products and Remediation section: Affected Versions, Updated Versions, and Link to Update
3.02022-04-20Updated Affected Products and Remediation sections: Updated Versions and Link to Update.

Informazioni correlate

Prodotti interessati

PowerStore, PowerStore 1000X, PowerStore 1000T, PowerStore 3000X, PowerStore 3000T, PowerStore 5000X, PowerStore 5000T, PowerStore 500T, PowerStore 7000X, PowerStore 7000T, PowerStore 9000X, PowerStore 9000T, Product Security Information
Proprietà dell'articolo
Numero articolo: 000194739
Tipo di articolo: Dell Security Advisory
Ultima modifica: 21 apr 2022
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.