DSA-2020-065: Dell EMC Unisphere for PowerMax, Dell EMC Unisphere for PowerMax Virtual Appliance, and Dell EMC PowerMax Embedded Management Update for Multiple Vulnerabilities

摘要: Dell EMC Unisphere for PowerMax, Dell EMC Unisphere for PowerMax Virtual Appliance, and Dell EMC PowerMax Embedded Management contains remediation for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. ...

本文适用于 本文不适用于 本文并非针对某种特定的产品。 本文并非包含所有产品版本。

影响

High

详情

Proprietary Code CVE(s) Description CVSSBase Score CVSS Vector String
CVE-2020-5367

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit. 


Note: This CVE was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17. CVE-2021-21548 addresses incomplete fix for CVE-2020-5367. 

7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2020-5345 Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics. 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Proprietary Code CVE(s) Description CVSSBase Score CVSS Vector String
CVE-2020-5367

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit. 


Note: This CVE was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17. CVE-2021-21548 addresses incomplete fix for CVE-2020-5367. 

7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2020-5345 Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics. 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Dell Technologies 建议所有客户考虑 CVSS 基本分数以及任何相关的时间和环境分数,这可能会影响与特定安全漏洞相关的潜在严重程度。

受影响的产品和补救措施

Product Affected Version(s) Updated Version(s) Link to Update
Unisphere for PowerMax Versions prior to 9.1.0.17 9.1.0.27
EEM: 9.1.0.856
https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers
Unisphere for PowerMax Virtual Appliance Versions prior to 9.1.0.17 9.1.0.27
EEM: 9.1.0.856
https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers
PowerMax OS 5978 5978 Request OPT 583679 for Foxtail SR and Hickory SR
Notes:
  • CVE-2020-5367 was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17.
  • DSA-2021-134 addresses the improper certificate validation vulnerability in the Dell EMC Unisphere for PowerMax version 9.1.0.27(CVE-2021-21548).
  • Dell EMC highly recommends all users upgrade Dell EMC Unisphere for PowerMax to version 9.1.0.27 at their earliest opportunity.
Product Affected Version(s) Updated Version(s) Link to Update
Unisphere for PowerMax Versions prior to 9.1.0.17 9.1.0.27
EEM: 9.1.0.856
https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers
Unisphere for PowerMax Virtual Appliance Versions prior to 9.1.0.17 9.1.0.27
EEM: 9.1.0.856
https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers
PowerMax OS 5978 5978 Request OPT 583679 for Foxtail SR and Hickory SR
Notes:
  • CVE-2020-5367 was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17.
  • DSA-2021-134 addresses the improper certificate validation vulnerability in the Dell EMC Unisphere for PowerMax version 9.1.0.27(CVE-2021-21548).
  • Dell EMC highly recommends all users upgrade Dell EMC Unisphere for PowerMax to version 9.1.0.27 at their earliest opportunity.

解决方法和缓解措施

None.

修订历史记录

RevisionDateDescription
1.02021-04-09Initial Release
2.0 2021-10-04Affected Component Type, CVE description, and Version Updated.  Added note to Affected Products and Remediation section concerning CVE-2021-21548 addresses incomplete fix for CVE-2020-5367. 

确认

CVE-2020-5367: Dell would like to thank Thorsten Tüllmann from Karlsruhe Institute of Technology, Germany for reporting this issue.

相关信息

受影响的产品

Unisphere for PowerMax

产品

PowerMax 2000, PowerMax 8000, Product Security Information, Unisphere for PowerMax
文章属性
文章编号: 000153935
文章类型: Dell Security Advisory
上次修改时间: 04 10月 2021
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。