DSA-2021-186: PowerPath Windows Security Update for OpenSSL_Configuration Utility Vulnerabilities
Summary: OpenSSL_Configuration Utility for PowerPath Windows contains remediation for SM2 Decryption Buffer Overflow and Read buffer overruns processing ASN.1 strings vulnerabilities that could be exploited by malicious users to compromise the affected systems. OpenSSL is being used for communication between PowerPath Windows host and Management server. OpenSSL is not bundled in PowerPath Windows package. However, separate compiled OpenSSL libraries are provided to customers through Dell EMC download site along with an installation script so that customers can install them separately. As vulnerability has been disclosed in the OpenSSL versions, as a remediation PowerPath engineering will update the download site with the latest OpenSSL libraries. ...
Bu makale şunlar için geçerlidir:
Bu makale şunlar için geçerli değildir:
Bu makale, belirli bir ürüne bağlı değildir.
Bu makalede tüm ürün sürümleri tanımlanmamıştır.
Impact
High
Details
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
| Third-Party Component |
CVE(s) | More information |
| Third-Party Component | CVE-2021-3711 | https://nvd.nist.gov/vuln/detail/CVE-2021-3711 |
| Third-Party Component | CVE-2021-3712 | https://nvd.nist.gov/vuln/detail/CVE-2021-3712 |
Etkilenen Ürünler ve Düzeltme
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-3711 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
| CVE-2021-3712 | PowerPath Windows |
OpenSSL_Configuration Utility | OpenSSL_Configuration Utility 2.0 | https://www.dell.com/support/home/en-in/product-support/product/powerpath-for-windows/drivers |
Geçici Çözümler ve Risk Azaltma
None
Revision History
| Revision | Date | Description |
| 1.0 | 2021-09-16 | Initial Release |
Related Information
Yasal Uyarı
Etkilenen Ürünler
Product Security InformationMakale Özellikleri
Article Number: 000191543
Article Type: Dell Security Advisory
Son Değiştirme: 21 Kas 2025
Sorularınıza diğer Dell kullanıcılarından yanıtlar bulun
Destek Hizmetleri
Aygıtınızın Destek Hizmetleri kapsamında olup olmadığını kontrol edin.