DSA-2024-194: Security Update for Dell PowerFlex Rack Multiple Third-Party Component Vulnerabilities
Riepilogo: Dell PowerFlex Rack remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Questo articolo si applica a
Questo articolo non si applica a
Questo articolo non è legato a un prodotto specifico.
Non tutte le versioni del prodotto sono identificate in questo articolo.
Impatto
High
Dettagli
| Third-party Component | CVEs | More Information |
|---|---|---|
| Dell PowerEdge Server BIOS | CVE-2023-32460, CVE-2023-23583,CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237, CVE-2023-20592, CVE-2024-0172 | DSA-2023-361 DSA-2023-370 DSA-2023-357 DSA-2023-391 DSA-2024-035 |
| CloudLink | CVE-2023-20593, CVE-2023-31085, CVE-2023-39189, CVE-2023-39192, CVE-2023-39193, CVE-2023-39194, CVE-2023-42754, CVE-2023-45862, CVE-2023-45871, CVE-2023-5717 | https://nvd.nist.gov/vuln/search |
| Cisco Switches | CVE-2024-20294, CVE-2024-20291, CVE-2024-20267, CVE-2022-41742, CVE-2022-41741, CVE-2021-3618, CVE-2017-20005, CVE-2021-23017, CVE-2019-20372, CVE-2018-16845, CVE-2017-7529, CVE-2016-1247, CVE-2016-4450, CVE-2016-0747, CVE-2016-0746, CVE-2016-0742 | Cisco Advisories; |
| VMWare | CVE-2024-22252, CVE-2024-22253,CVE-2024-22254, CVE-2024-22255 | VMSA-2024-0006.1; |
| NetBIOS | CVE-2023-0673 | https://nvd.nist.gov/vuln/search |
| OpenSSH | CVE-2023-48795 | https://nvd.nist.gov/vuln/search |
| cURL | CVE-2023-28545 | https://nvd.nist.gov/vuln/search |
Prodotti interessati e correzione
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| PowerFlex Rack | RCM | Versions prior to 3.6.6.0 | Version 3.6.6.0 | RCM release |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| PowerFlex Rack | RCM | Versions prior to 3.6.6.0 | Version 3.6.6.0 | RCM release |
Cronologia delle revisioni
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-04-24 | Initial Release |
| 2.0 | 2024-04-29 | Added CVE-2023-48795 |
| 3.0 | 2025-02-07 | Corrected the name of the external dependency for CVE-2023-48795 |
| 4.0 | 2025-02-20 | Major Update: CVE-2023-38545 added as remediated in the initial release |
Informazioni correlate
Dichiarazione di non responsabilità
Prodotti interessati
PowerFlex rack, PowerFlex rack connectivity, PowerFlex rack HW, PowerFlex rack RCM Software, Product Security InformationProprietà dell'articolo
Numero articolo: 000224465
Tipo di articolo: Dell Security Advisory
Ultima modifica: 20 feb 2025
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.