DSA-2023-283: Security Update for Dell SmartFabric Storage Software Vulnerabilities

概要: Dell SmartFabric Storage Software remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

この記事は次に適用されます: この記事は次には適用されません: この記事は、特定の製品に関連付けられていません。 すべての製品パージョンがこの記事に記載されているわけではありません。

影響

Critical

詳細

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-32485 Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability affecting user authentication. Dell recommends customers to upgrade at the earliest opportunity. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-32485 Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability affecting user authentication. Dell recommends customers to upgrade at the earliest opportunity. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
デル・テクノロジーズでは、すべてのお客様に対して、CVSSベース スコアに加えて、特定のセキュリティの脆弱性に付随する潜在的な重要度に影響する可能性のある現状スコアや環境スコアも考慮することをお勧めしています。

影響を受ける製品と修復

CVEs Addressed Product Affected Versions Remediated Versions Link
 CVE-2023-32485 Dell SmartFabric Storage Software Versions before 1.4.0  1.4.0  https://www.dell.com/support
CVEs Addressed Product Affected Versions Remediated Versions Link
 CVE-2023-32485 Dell SmartFabric Storage Software Versions before 1.4.0  1.4.0  https://www.dell.com/support

回避策と緩和策

none

変更履歴

RevisionDateDescription
1.02023-08-08Initial Release
2.02023-10-05Major Revision: added relevant URL to the CVEand modified minor formatting without content change.

関連情報

対象製品

SmartFabric Storage Software for NVMe/TCP SAN, SmartFabric Storage Software Download for NVMe/TCP SAN
文書のプロパティ
文書番号: 000216587
文書の種類: Dell Security Advisory
最終更新: 05 10月 2023
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。