DSA-2024-047: Security Update for Dell SmartFabric Storage Software Vulnerabilities.

요약: Dell SmartFabric Storage Software remediation is available for Multiple Security Vulnerabilities that could be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Critical

세부 정보

Third-party Component  CVEs  More Information 
OpenSSH CVE-2023-38408, CVE-2023-41617, CVE-2023-48795, CVE-2023-51385 See NVD link below for individual scores for each CVE.  https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
ncurses CVE-2023-29491 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
golang.org/x/sys CVE-2022-29526 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
golang.org/x/text CVE-2022-32149 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
golang.org.x.et CVE-2023-39325, CVE-2023-3978, CVE-2023-44487 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
golang.or/x/net CVE-2023-39325, CVE-2023-3978, CVE-2023-44487, CVE-2021-33194, CVE-2022-27664, CVE-2022-41723, CVE-2021-31525 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
golang.org/rpc CVE-2023-44487 GitHub Security AdvisoryThis hyperlink is taking you to a website outside of Dell Technologies.
mariadb CVE-2022-47015

 
See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
Linux kernel CVE-2023-1989, CVE-2023-35827, CVE-2023-4244, CVE-2023-42753, CVE-2023-45871, CVE-2023-4622, CVE-2023-4623, CVE-2023-46813, CVE-2023-4921, CVE-2023-5178, CVE-2023-5717, CVE-2023-6176, CVE-2023-6531, CVE-2023-6817, CVE-2023-6932, CVE-2021-44879, CVE-2023-20588, CVE-2023-34324, CVE-2023-37453, CVE-2023-3772, CVE-2023-3773, CVE-2023-39189, CVE-2023-39192, CVE-2023-39194, CVE-2023-42754, CVE-2023-42755, CVE-2023-42756, CVE-2023-45863, CVE-2023-46862, CVE-2023-5197, CVE-2023-6121, CVE-2024-0193, CVE-2023-51780, CVE-2023-51781, CVE-2023-51782 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
glibc CVE-2023-4911 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
runc CVE-2022-29162 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
bind CVE-2023-3341 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
openssl CVE-2023-3446, CVE-2023-3817
 
See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
dbus CVE-2023-34969 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
krb5 CVE-2023-36054
 
See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
cURL CVE-2023-38545, CVE-2023-27533, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536, CVE-2023-27538, CVE-2023-28321, CVE-2023-38546 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
exim4 CVE-2023-42115, CVE-2023-42116, CVE-2023-51766, CVE-2023-42114


 
See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
See  Debian Security Tracker for details
Debian Security TrackerThis hyperlink is taking you to a website outside of Dell Technologies.
libx11-6 CVE-2023-43787, CVE-2023-43785, CVE-2023-43786 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
libxpm4 CVE-2023-43788, CVE-2023-43789 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
libnghttp2-14 CVE-2023-44487 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
libwebp6 CVE-2023-4863 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
paramiko
CVE-2023-48795
See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2023-38408, CVE-2023-41617, CVE-2023-48795, CVE-2023-51385 SmartFabric Storage Software Versions prior to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-29491 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-29526 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-32149 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-39325, CVE-2023-3978, CVE-2023-44487 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-39325, CVE-2023-3978, CVE-2023-44487, CVE-2021-33194, CVE-2022-27664, CVE-2022-41723, CVE-2021-31525 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-44487 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-47015
 
SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-1989, CVE-2023-35827, CVE-2023-4244, CVE-2023-42753, CVE-2023-45871, CVE-2023-4622, CVE-2023-4623, CVE-2023-46813, CVE-2023-4921, CVE-2023-5178, CVE-2023-5717, CVE-2023-6176, CVE-2023-6531, CVE-2023-6817, CVE-2023-6932, CVE-2021-44879, CVE-2023-20588, CVE-2023-34324, CVE-2023-37453, CVE-2023-3772, CVE-2023-3773, CVE-2023-39189, CVE-2023-39192, CVE-2023-39194, CVE-2023-42754, CVE-2023-42755, CVE-2023-42756, CVE-2023-45863, CVE-2023-46862, CVE-2023-5197, CVE-2023-6121, CVE-2024-0193, CVE-2023-51780, CVE-2023-51781, CVE-2023-51782 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-4911 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-29162 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-3341 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-3446, CVE-2023-3817 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-34969 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-36054 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-38545, CVE-2023-27533, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536, CVE-2023-27538, CVE-2023-28321, CVE-2023-38546 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-42115, CVE-2023-42116, CVE-2023-51766, CVE-2023-42114
 
SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-43787, CVE-2023-43785, CVE-2023-43786 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-43788, CVE-2023-43789 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-44487 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-4863 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download

CVE-2023-48795
SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2023-38408, CVE-2023-41617, CVE-2023-48795, CVE-2023-51385 SmartFabric Storage Software Versions prior to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-29491 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-29526 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-32149 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-39325, CVE-2023-3978, CVE-2023-44487 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-39325, CVE-2023-3978, CVE-2023-44487, CVE-2021-33194, CVE-2022-27664, CVE-2022-41723, CVE-2021-31525 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-44487 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-47015
 
SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-1989, CVE-2023-35827, CVE-2023-4244, CVE-2023-42753, CVE-2023-45871, CVE-2023-4622, CVE-2023-4623, CVE-2023-46813, CVE-2023-4921, CVE-2023-5178, CVE-2023-5717, CVE-2023-6176, CVE-2023-6531, CVE-2023-6817, CVE-2023-6932, CVE-2021-44879, CVE-2023-20588, CVE-2023-34324, CVE-2023-37453, CVE-2023-3772, CVE-2023-3773, CVE-2023-39189, CVE-2023-39192, CVE-2023-39194, CVE-2023-42754, CVE-2023-42755, CVE-2023-42756, CVE-2023-45863, CVE-2023-46862, CVE-2023-5197, CVE-2023-6121, CVE-2024-0193, CVE-2023-51780, CVE-2023-51781, CVE-2023-51782 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-4911 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2022-29162 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-3341 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-3446, CVE-2023-3817 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-34969 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-36054 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-38545, CVE-2023-27533, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536, CVE-2023-27538, CVE-2023-28321, CVE-2023-38546 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-42115, CVE-2023-42116, CVE-2023-51766, CVE-2023-42114
 
SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-43787, CVE-2023-43785, CVE-2023-43786 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-43788, CVE-2023-43789 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-44487 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download
CVE-2023-4863 SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download

CVE-2023-48795
SmartFabric Storage Software Versions prior to to 1.4.2 1.4.2 SmartFabric Storage Software Download

해결 방법 및 완화 방안

None

개정 내역

Revision DateDescription
1.02024-02-07Initial Release
2.02024-02-15Updating the title to reflect year 2024
3.02024-05-22Updated for enhanced presentation with no other changes to content.

관련 정보

해당 제품

SmartFabric Storage Software Download for NVMe/TCP SAN
문서 속성
문서 번호: 000221912
문서 유형: Dell Security Advisory
마지막 수정 시간: 22 5월 2024
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.