DSA-2026-246: Security Update for Dell UCC Edge Multiple Vulnerabilities
概要: Dell UCC Edge remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
この記事は次に適用されます:
この記事は次には適用されません:
この記事は、特定の製品に関連付けられていません。
すべての製品パージョンがこの記事に記載されているわけではありません。
影響
High
詳細
| Third-party Component | CVEs | ; More Information |
| Python; | CVE-2025-0938, CVE-2025-47273, CVE-2025-13836; | https://nvd.nist.gov/vuln/search |
| XZ Utils; | CVE-2025-31115 | https://nvd.nist.gov/vuln/search |
| urllib3; | CVE-2025-50181 | https://nvd.nist.gov/vuln/search |
| ESE; | CVE-2026-26950 | https://nvd.nist.gov/vuln/search |
| Linux Kernel | CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, CVE-2026-46300, CVE-2026-46333 | https://nvd.nist.gov/vuln/search |
| OpenSSH | CVE-2025-61984, CVE-2025-61985, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 | https://nvd.nist.gov/vuln/search |
| Kubernetes | CVE-1999-0511 | https://nvd.nist.gov/vuln/search |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-49503 | Dell UCC Edge, versions prior to 3.0.2, contains an Insufficiently Protected Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. | 5.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| CVE-2026-49504 | Dell UCC Edge, versions prior to 3.0.2, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution. | 4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-49503 | Dell UCC Edge, versions prior to 3.0.2, contains an Insufficiently Protected Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. | 5.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| CVE-2026-49504 | Dell UCC Edge, versions prior to 3.0.2, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution. | 4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
影響を受ける製品と修復
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell UCC Edge | Versions prior to 3.0.2 |
Version 3.0.2 or later
|
Support for UCC Edge | Drivers & Downloads | Dell US |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell UCC Edge | Versions prior to 3.0.2 |
Version 3.0.2 or later
|
Support for UCC Edge | Drivers & Downloads | Dell US |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
回避策と緩和策
None
変更履歴
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-08-19 | Initial |
関連情報
法的免責事項
文書のプロパティ
文書番号: 000501633
文書の種類: Dell Security Advisory
最終更新: 19 8月 2026
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。