DSA-2024-194: Security Update for Dell PowerFlex Rack Multiple Third-Party Component Vulnerabilities
Zhrnutie: Dell PowerFlex Rack remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Tento článok sa vzťahuje na
Tento článok sa nevzťahuje na
Tento článok nie je viazaný na žiadny konkrétny produkt.
V tomto článku nie sú uvedené všetky verzie produktov.
Dosah
High
Podrobnosti
| Third-party Component | CVEs | More Information |
|---|---|---|
| Dell PowerEdge Server BIOS | CVE-2023-32460, CVE-2023-23583,CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237, CVE-2023-20592, CVE-2024-0172 | DSA-2023-361 DSA-2023-370 DSA-2023-357 DSA-2023-391 DSA-2024-035 |
| CloudLink | CVE-2023-20593, CVE-2023-31085, CVE-2023-39189, CVE-2023-39192, CVE-2023-39193, CVE-2023-39194, CVE-2023-42754, CVE-2023-45862, CVE-2023-45871, CVE-2023-5717 | https://nvd.nist.gov/vuln/search |
| Cisco Switches | CVE-2024-20294, CVE-2024-20291, CVE-2024-20267, CVE-2022-41742, CVE-2022-41741, CVE-2021-3618, CVE-2017-20005, CVE-2021-23017, CVE-2019-20372, CVE-2018-16845, CVE-2017-7529, CVE-2016-1247, CVE-2016-4450, CVE-2016-0747, CVE-2016-0746, CVE-2016-0742 | Cisco Advisories; |
| VMWare | CVE-2024-22252, CVE-2024-22253,CVE-2024-22254, CVE-2024-22255 | VMSA-2024-0006.1; |
| NetBIOS | CVE-2023-0673 | https://nvd.nist.gov/vuln/search |
| OpenSSH | CVE-2023-48795 | https://nvd.nist.gov/vuln/search |
| cURL | CVE-2023-28545 | https://nvd.nist.gov/vuln/search |
Dotknuté produkty a riešenie problému
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| PowerFlex Rack | RCM | Versions prior to 3.6.6.0 | Version 3.6.6.0 | RCM release |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| PowerFlex Rack | RCM | Versions prior to 3.6.6.0 | Version 3.6.6.0 | RCM release |
História revízií
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-04-24 | Initial Release |
| 2.0 | 2024-04-29 | Added CVE-2023-48795 |
| 3.0 | 2025-02-07 | Corrected the name of the external dependency for CVE-2023-48795 |
| 4.0 | 2025-02-20 | Major Update: CVE-2023-38545 added as remediated in the initial release |
Súvisiace informácie
Legal Disclaimer
Dotknuté produkty
PowerFlex rack, PowerFlex rack connectivity, PowerFlex rack HW, PowerFlex rack RCM Software, Product Security InformationVlastnosti článku
Číslo článku: 000224465
Typ článku: Dell Security Advisory
Dátum poslednej úpravy: 20 feb 2025
Nájdite odpovede na svoje otázky od ostatných používateľov spoločnosti Dell
Služby podpory
Skontrolujte, či sa na vaše zariadenie vzťahujú služby podpory.