DSA-2026-165: Security Update for Dell AppSync Vulnerabilities.

Riepilogo: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

High

Dettagli

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-27110 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28257 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28258 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-27110 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28257 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-28258 Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2026-27110, CVE-2026-28257, CVE-2026-28258 Dell AppSync 4.6.0.4, 4.6.1.0 4.6.1.1 https://www.dell.com/support/product-details/en-us/product/appsync/drivers
CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2026-27110, CVE-2026-28257, CVE-2026-28258 Dell AppSync 4.6.0.4, 4.6.1.0 4.6.1.1 https://www.dell.com/support/product-details/en-us/product/appsync/drivers

Soluzioni alternative e mitigazioni

n/a

Cronologia delle revisioni

Revision

Date

Description

1.0

2026-08-24

Initial Release

 

Ringraziamenti

Dell would like to thank brocked200 for reporting this issue.

Informazioni correlate

Prodotti interessati

AppSync
Proprietà dell'articolo
Numero articolo: 000502484
Tipo di articolo: Dell Security Advisory
Ultima modifica: 24 ago 2026
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.