DSA-2024-416: Security Update for Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software for Multiple Third-Party Component Vulnerabilities
요약: Dell APEX Cloud Platform for Microsoft Azure remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. ...
영향
High
세부 정보
|
Third-party Component |
CVEs |
More Information |
|
Dell PowerEdge Server Security Update for Intel Ethernet Controllers & Adapters and Intel Processor Vulnerabilities |
CVE-2024-24852, CVE-2024-36274 |
|
|
Dell PowerEdge Server Security Update for Intel Ethernet Controllers & Adapters and TDX Software Vulnerabilities |
CVE-2024-22374, CVE-2024-22376, CVE-2024-21810, CVE-2024-23497, CVE-2024-23981, CVE-2024-24986, CVE-2024-21807, CVE-2024-21769, CVE-2024-24983, CVE-2024-23499, CVE-2024-21806 |
|
|
Dell iDRAC Service Module 7-Zip Vulnerability |
CVE-2023-31102, CVE-2023-40481 |
|
|
Dell PowerEdge Server for Intel 2024 Security Advisories |
CVE-2023-43753, CVE-2023-41833 |
영향을 받는 제품 및 문제 해결
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Microsoft Azure Stack HCI |
Versions prior to 10.2408.1 |
Version 10.2408.1 or later |
|
|
Dell Apex Cloud Platform for Microsoft Azure |
Versions prior to 01.03.00.00 |
Version 01.03.00.00 or later |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Microsoft Azure Stack HCI |
Versions prior to 10.2408.1 |
Version 10.2408.1 or later |
|
|
Dell Apex Cloud Platform for Microsoft Azure |
Versions prior to 01.03.00.00 |
Version 01.03.00.00 or later |
To apply patch for Dell iDRAC Service Module 7-Zip Vulnerability, refer to the instructions provided in Workarounds and Mitigations Section.
해결 방법 및 완화 방안
|
CVE ID |
MITIGATION |
|
CVE-2023-31102, CVE-2023-40481 |
How to manually patch iSM security hotfix after LCM to 01.03.x.x release |
개정 내역
|
Revision |
Date |
Description |
|
1.0 |
2024-10-18 |
Initial Release |
|
2.0 |
2025-02-27 |
Added CVE-2024-24852, CVE-2024-36274 for Intel Ethernet Controllers & Adapters |