DSA-2024-491: Security Update for Dell InsightIQ Multiple Security Vulnerabilities
Resumo: Dell InsightIQ remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impacto
Medium
Dados
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-53293 |
Dell InsightIQ version 5.1 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access. |
6.7 |
|
| CVE-2024-47979 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
5.6 |
|
| CVE-2024-53294 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
5.3 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|---|---|---|---|
| CVE-2024-53293 |
Dell InsightIQ version 5.1 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access. |
6.7 |
|
| CVE-2024-47979 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
5.6 |
|
| CVE-2024-53294 |
Dell InsightIQ versions 5.0 through 5.1 contains an improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
5.3 |
Produtos afetados e soluções
| Product |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|
| PowerScale InsightIQ |
Versions 5.0.0 through 5.1.x |
Version 5.2.0 or later |
| Product |
Affected Versions |
Remediated Versions |
Link |
|---|---|---|---|
| PowerScale InsightIQ |
Versions 5.0.0 through 5.1.x |
Version 5.2.0 or later |
Histórico de revisão
| Revision | Date | Description |
|---|---|---|
|
1.0 | 2025-01-09 | Initial Release |
|
2.0 | 2025-01-09 |
Updated for enhanced presentation with no changes to content |