DSA-2021-186: PowerPath Windows Security Update for OpenSSL_Configuration Utility Vulnerabilities
Samenvatting: OpenSSL_Configuration Utility for PowerPath Windows contains remediation for SM2 Decryption Buffer Overflow and Read buffer overruns processing ASN.1 strings vulnerabilities that could be exploited by malicious users to compromise the affected systems. OpenSSL is being used for communication between PowerPath Windows host and Management server. OpenSSL is not bundled in PowerPath Windows package. However, separate compiled OpenSSL libraries are provided to customers through Dell EMC download site along with an installation script so that customers can install them separately. As vulnerability has been disclosed in the OpenSSL versions, as a remediation PowerPath engineering will update the download site with the latest OpenSSL libraries. ...
Dit artikel is van toepassing op
Dit artikel is niet van toepassing op
Dit artikel is niet gebonden aan een specifiek product.
Niet alle productversies worden in dit artikel vermeld.
Impact
High
Gegevens
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
Getroffen producten en herstel
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
Tijdelijke oplossingen en risicobeperking
None
Revisiegeschiedenis
| Revision | Date | Description |
| 1.0 | 2021-09-16 | Initial Release |
Verwante informatie
Juridische verklaring van afstand
Getroffen producten
Product Security InformationArtikeleigenschappen
Artikelnummer: 000191543
Artikeltype: Dell Security Advisory
Laatst aangepast: 21 nov. 2025
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.