DSA-2022-254: Dell System Update (DSU) Security Update for a Self-Signed Certificate Vulnerability
摘要: Dell System Update (DSU) remediation is available for a self-signed certificate vulnerability that could be exploited by malicious users to compromise the affected system.
本文适用于
本文不适用于
本文并非针对某种特定的产品。
本文并非包含所有产品版本。
影响
Medium
详情
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34404 | Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-34404 | Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
受影响的产品和补救措施
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2022-34404 | DSU |
Versions prior to 2.0.1.0 |
2.0.1.0 or later | https://www.dell.com/support/product-details/product/system-update/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2022-34404 | DSU |
Versions prior to 2.0.1.0 |
2.0.1.0 or later | https://www.dell.com/support/product-details/product/system-update/drivers |
解决方法和缓解措施
None.
修订历史记录
| Revision | Date | Description |
| 1.0 | 2022-09-26 | Initial Release |
相关信息
法律免责声明
受影响的产品
Dell System Update v1.3, Dell System update v1.3.1, Dell System Update v1.1, Dell System Update v1.2, Product Security Information, Dell System update v1.4.0文章属性
文章编号: 000203733
文章类型: Dell Security Advisory
上次修改时间: 17 2月 2025
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。