DSA-2024-484: Security Update for Dell PowerFlex Appliance Multiple Third-Party Component Vulnerabilities

概要: Dell PowerFlex Appliance remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

この記事は次に適用されます: この記事は次には適用されません: この記事は、特定の製品に関連付けられていません。 すべての製品パージョンがこの記事に記載されているわけではありません。

影響

Critical

詳細

Third-party Component CVEs More Information
Dell PowerEdge Server BIOS CVE-2023-45745, CVE-2023-47855, CVE-2023-31355, CVE-2024-21978, CVE-2024-21980, CVE-2023-31315, CVE-2023-49141, CVE-2021-26344, CVE-2021-26387, CVE-2021-46772, CVE-2021-46746, CVE-2023-20518, CVE-2023-20578, CVE-2023-20584, CVE-2023-20591, CVE-2023-31356, CVE-2024-21981, CVE-2024-21801, CVE-2024-22374 DSA-2024-160, DSA-2024-306, DSA-2024-344, DSA-2024-160, DSA-2024-350, DSA-2024-359
iDRAC CVE-2024-25943, CVE-2023-48795, CVE-2024-38433, CVE-2024-6387, CVE-2023-29499 DSA-2024-099, DSA-2024-021, DSA-2024-223, DSA-2024-342, DSA-2024-286
VMWare CVE-2024-22273, CVE-2024-22274, CVE-2024-22275, CVE-2024-37086, CVE-2024-37087, CVE-2024-37085, CVE-2024-38812, CVE-2024-38813 VMSA-2024-0011This hyperlink is taking you to a website outside of Dell Technologies., VMSA-2024-0013This hyperlink is taking you to a website outside of Dell Technologies., VMSA-2024-0013This hyperlink is taking you to a website outside of Dell Technologies., VMSA-2024-0019This hyperlink is taking you to a website outside of Dell Technologies.
CUPS CVE-2024-47176, CVE-2024-47076 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.
Python-cryptography CVE-2023-50782 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.
libexpat CVE-2023-52425 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.
openssl CVE-2016-2183 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.
SQLParse CVE-2023-20608 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.
OpenJDK CVE-2024-21094 https://nvd.nist.gov/vuln/searchThis hyperlink is taking you to a website outside of Dell Technologies.

デル・テクノロジーズでは、すべてのお客様に対して、CVSSベース スコアに加えて、特定のセキュリティの脆弱性に付随する潜在的な重要度に影響する可能性のある現状スコアや環境スコアも考慮することをお勧めしています。

影響を受ける製品と修復

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

PowerFlex appliance

IC

Versions prior to IC 46.376.00

 

Version IC 46.376.00 or later

 

IC Release

PowerFlex appliance

IC

Versions prior to IC 46.381.00

Version IC 46.381.00 or laer

IC Release

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

PowerFlex appliance

IC

Versions prior to IC 46.376.00

 

Version IC 46.376.00 or later

 

IC Release

PowerFlex appliance

IC

Versions prior to IC 46.381.00

Version IC 46.381.00 or laer

IC Release

変更履歴

RevisionDateDescription
1.02024-12-12Initial Release
2.02025-02-20Major update; remediation content:
CVE-2023-50782,CVE-2023-52425,CVE-2016-2183, CVE-2023-30608,CVE-2024-21094 added as remediated since the initial release
3.02025-03-24Updated for enhanced presentation with no changes to content
4.02026-01-29
Updated advisory to ensure accurate version tracking

関連情報

対象製品

PowerFlex Appliance, PowerFlex appliance Intelligent Catalog Software
文書のプロパティ
文書番号: 000259574
文書の種類: Dell Security Advisory
最終更新: 29 1月 2026
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。