DSA-2023-145: Dell PowerFlex rack Security Update for Multiple Third-Party Vulnerabilities

Riepilogo: Dell PowerFlex rack remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

Critical

Dettagli

Third-party Component CVEs More information
Intel 500 Series Adapters CVE-2022-36416, CVE-2022-36797 https://nvd.nist.gov/vuln/detail/222-36416This hyperlink is taking you to a website outside of Dell Technologies., https://nvd.nist.gov/vuln/detail/CVE-2022-36797This hyperlink is taking you to a website outside of Dell Technologies.
Intel 710 Series Adapters CVE-2021-33126 https://nvd.nist.gov/vuln/detail/CVE-2021-33126This hyperlink is taking you to a website outside of Dell Technologies.
ESXi CVE-2022-31705 VMSA-2022-0033This hyperlink is taking you to a website outside of Dell Technologies.
Dell PowerEdge Server BIOS CVE-2022-36794, CVE-2022-30539, CVE-2022-32231, CVE-2022-26837, CVE-2022-30704, CVE-2021-0187, CVE-2022-26343, CVE-2022-36348, CVE-2022-33196, CVE-2022-33972, CVE-2022-21216, CVE-2022-38090 DSA-2023-014
ESXi CVE-2022-31696 VMSA-2022-0030This hyperlink is taking you to a website outside of Dell Technologies.
vCenter Server CVE-2022-31697 VMSA-2022-0030This hyperlink is taking you to a website outside of Dell Technologies.
Cisco Switches CVE-2023-20050 https://nvd.nist.gov/vuln/detail/CVE-2023-20050This hyperlink is taking you to a website outside of Dell Technologies.
Dell PowerEdge Server BIOS CVE-2021-46769, CVE-2021-26354, CVE-2021-26371, CVE-2021-26379, CVE-2021-46763, CVE-2021-46756, CVE-2021-46764, CVE-2021-26356, CVE-2021-26406, CVE-2021-46775, CVE-2023-20524, CVE-2021-46762, CVE-2022-23818, CVE-2021-26397, CVE-2023-20520 DSA-2023-105

Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Product Software/Firmware Affected Versions Remediated Versions  Link
PowerFlex rack RCM Versions prior to 3.6.3.2   Version 3.6.3.2 https://vce.flexnetoperations.com/control/vcec/product?plneID=740417
Product Software/Firmware Affected Versions Remediated Versions  Link
PowerFlex rack RCM Versions prior to 3.6.3.2   Version 3.6.3.2 https://vce.flexnetoperations.com/control/vcec/product?plneID=740417

Soluzioni alternative e mitigazioni

None.

Cronologia delle revisioni

Revision  Date Description
1.0 2023-04-28  Initial Release
2.0 2023-05-21 Added CVEs impacted
3.02023-09-01Updated for enhanced presentation with no changes to content.

Informazioni correlate

Prodotti interessati

PowerFlex rack
Proprietà dell'articolo
Numero articolo: 000213224
Tipo di articolo: Dell Security Advisory
Ultima modifica: 01 set 2023
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.