DSA-2021-125: Dell EMC NetWorker Security Update for Multiple Vulnerabilities

요약: Dell EMC NetWorker remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Medium

세부 정보

 
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2021-21600 Dell NetWorker 19.4 or earlier contains an uncontrolled resource consumption flaw in its API service. An authorized API user may potentially exploit this vulnerability using the web and desktop user interfaces, leading to denial of service in the manageability path. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
 
Third-Party Component CVEs More Information
OpenSSL CVE-2020-1971 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
Apache Tomcat CVE-2020-1935
CVE-2021-24122

 
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2021-21600 Dell NetWorker 19.4 or earlier contains an uncontrolled resource consumption flaw in its API service. An authorized API user may potentially exploit this vulnerability using the web and desktop user interfaces, leading to denial of service in the manageability path. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
 
Third-Party Component CVEs More Information
OpenSSL CVE-2020-1971 See NVD (http://nvd.nist.gov/) for individual scores for each CVE.
Apache Tomcat CVE-2020-1935
CVE-2021-24122

Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-21600 Dell EMC NetWorker 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x prior to 19.4.0.4.
  • 19.4.0.4
  • 19.5.0 and later.
https://www.dell.com/support/home/en-in/product-support/product/networker/drivers
CVE-2020-1971 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x.  19.5.0 and later.
CVE-2020-1935
CVE-2021-24122
CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-21600 Dell EMC NetWorker 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x prior to 19.4.0.4.
  • 19.4.0.4
  • 19.5.0 and later.
https://www.dell.com/support/home/en-in/product-support/product/networker/drivers
CVE-2020-1971 18.x, 19.1.x, 19.2.x 19.3.x, and 19.4.x.  19.5.0 and later.
CVE-2020-1935
CVE-2021-24122

개정 내역

RevisionDateDescription
1.02021-07-20Initial Release
1.12021-09-02Updated "Affected Products and Remediation" Section

감사의 말

CVE-2021-21600: Dell Technologies would like to thank J-M Roth for reporting this issue.

관련 정보

해당 제품

NetWorker, Product Security Information
문서 속성
문서 번호: 000189694
문서 유형: Dell Security Advisory
마지막 수정 시간: 02 9월 2021
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.