DSA-2022-196: Dell Cyber Recovery Security Update for Multiple Vulnerabilities

Riepilogo: Dell Cyber Recovery remediation is available for multiple security vulnerabilities that may potentially be exploited by malicious users to compromise the affected system.

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

Critical

Dettagli

Proprietary Code CVE Description CVSS Base score CVSS Vector String
CVE-2022-34372 Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
Third-party Component CVEs More information
Debian GNU/Linux, Alpine Linux See Release Notes See NVD (http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.) for individual scores for each CVE.
Proprietary Code CVE Description CVSS Base score CVSS Vector String
CVE-2022-34372 Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
Third-party Component CVEs More information
Debian GNU/Linux, Alpine Linux See Release Notes See NVD (http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.) for individual scores for each CVE.
Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Product Affected Versions Updated Versions Link to update
Cyber Recovery Versions before 19.11.0.2 19.11.0.2 Cyber Recovery Downloads
 
NOTE: Third-party vulnerabilities pertain to Golang packages and Cyber Recovery Docker containers. The proprietary vulnerability pertains to Cyber Recovery software on management host.
Product Affected Versions Updated Versions Link to update
Cyber Recovery Versions before 19.11.0.2 19.11.0.2 Cyber Recovery Downloads
 
NOTE: Third-party vulnerabilities pertain to Golang packages and Cyber Recovery Docker containers. The proprietary vulnerability pertains to Cyber Recovery software on management host.

Cronologia delle revisioni

RevisionDateDescription
1.02022-08-01Initial Release

Informazioni correlate

Prodotti interessati

PowerProtect Cyber Recovery

Prodotti

Product Security Information
Proprietà dell'articolo
Numero articolo: 000201970
Tipo di articolo: Dell Security Advisory
Ultima modifica: 19 set 2025
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.