DSA-2026-165: Security Update for Dell AppSync Vulnerabilities.
Summary: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Bu makale şunlar için geçerlidir:
Bu makale şunlar için geçerli değildir:
Bu makale, belirli bir ürüne bağlı değildir.
Bu makalede tüm ürün sürümleri tanımlanmamıştır.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-27110 | Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-28257 | Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | 7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
| CVE-2026-28258 | Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | 7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-27110 | Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-28257 | Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | 7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
| CVE-2026-28258 | Dell AppSync, version(s) 4.6.0.4, contain(s) an Improper Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | 7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Etkilenen Ürünler ve Düzeltme
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
| CVE-2026-27110, CVE-2026-28257, CVE-2026-28258 | Dell AppSync | 4.6.0.4, 4.6.1.0 | 4.6.1.1 | https://www.dell.com/support/product-details/en-us/product/appsync/drivers |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
| CVE-2026-27110, CVE-2026-28257, CVE-2026-28258 | Dell AppSync | 4.6.0.4, 4.6.1.0 | 4.6.1.1 | https://www.dell.com/support/product-details/en-us/product/appsync/drivers |
Geçici Çözümler ve Risk Azaltma
n/a
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2026-08-24 |
Initial Release |
Acknowledgements
Dell would like to thank brocked200 for reporting this issue.
Related Information
Yasal Uyarı
Etkilenen Ürünler
AppSyncMakale Özellikleri
Article Number: 000502484
Article Type: Dell Security Advisory
Son Değiştirme: 24 Ağu 2026
Sorularınıza diğer Dell kullanıcılarından yanıtlar bulun
Destek Hizmetleri
Aygıtınızın Destek Hizmetleri kapsamında olup olmadığını kontrol edin.