Ga naar hoofdinhoud
  • Snel en eenvoudig bestellen
  • Bestellingen en de verzendstatus bekijken
  • Een lijst met producten maken en openen
  • Beheer uw Dell EMC locaties, producten en contactpersonen op productniveau met Company Administration.

Artikelnummer: 000186363


DSA-2021-091: Dell EMC XtremIO Security Update for Multiple Vulnerabilities

Samenvatting: Dell EMC XtremIO remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Article content


Impact

High

Gegevens

Proprietary Code CVE(s) 

Description 

CVSSBase Score 

CVSS Vector String  

CVE-2021-21549 

Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to the vulnerable application, causing unintended server operations. 

8.8 

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 

 

Third-Party Component  

 

CVE(s) 

More information 

OpenSSL 

CVE-2020-1971 

See NVD (http://nvd.nist.gov/) for individual scores for each CVE 

Proprietary Code CVE(s) 

Description 

CVSSBase Score 

CVSS Vector String  

CVE-2021-21549 

Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to the vulnerable application, causing unintended server operations. 

8.8 

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 

 

Third-Party Component  

 

CVE(s) 

More information 

OpenSSL 

CVE-2020-1971 

See NVD (http://nvd.nist.gov/) for individual scores for each CVE 

Dell Technologies raadt aan dat alle klanten rekening houden met zowel de basisscore van CVSS als alle relevante tijdelijke en omgevingsscores die gevolgen kunnen hebben voor de mogelijke ernst van de specifieke beveiligingsproblemen.

Getroffen producten en herstel

CVE(s) Addressed 

Product 

Affected Version(s) 

Updated Version(s) 

Link to Update 

CVE-2020-1971 

XtremIO X1, XtremIO X2 

XMS versions prior to 6.3.3-8 

XMS 6.3.3-8 

Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can contact Dell EMC support to perform the upgrade. 

CVE-2021-21549 

CVE(s) Addressed 

Product 

Affected Version(s) 

Updated Version(s) 

Link to Update 

CVE-2020-1971 

XtremIO X1, XtremIO X2 

XMS versions prior to 6.3.3-8 

XMS 6.3.3-8 

Dell EMC recommends all customers upgrade at the earliest opportunity. Customers can contact Dell EMC support to perform the upgrade. 

CVE-2021-21549 

Tijdelijke oplossingen en beperkingen

None

Bevestigingen

CVE-2021-21549: Dell would like to thank Tomasz Stachowicz for reporting this issue.

Revisiegeschiedenis

Revision 

Date 

Description 

1.0 

2021-05-13 

Initial Release 

Verwante informatie

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide


Artikeleigenschappen


Getroffen product
XtremIO, Product Security Information, XtremIO Family, XtremIO HW Gen2 400GB, XtremIO HW Gen2 400GB Encrypt Capbl, XtremIO HW Gen2 400GB Encrypt Disable, XtremIO HW Gen2 400GB Exp Encrypt Disable, XtremIO HW Gen2 400GB Expandable , XtremIO HW Gen2 800GB Encrypt Capbl ...
Product
XtremIO HW Gen2 800GB Encrypt Disable, XtremIO HW Gen3 40TB, XtremIO HW Gen3 40TB Encrypt Disable, XtremIO HW X2-R, XtremIO HW X2-R Encrypt Disable, XtremIO HW X2-S, XtremIO HW X2-S Encrypt Disable, XtremIO HW X2-T, XtremIO HW X2-T Encrypt Disable , XtremIO X1, XtremIO X2 ...
Datum laatst gepubliceerd

13 mei 2021

Versie

1

Artikeltype

Dell Security Advisory