DSA-2026-163: Security Update for Dell AppSync Vulnerabilities

摘要: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

本文适用于 本文不适用于 本文并非针对某种特定的产品。 本文并非包含所有产品版本。

影响

High

详情

Third-party Component CVEs More Information
KEYCLOAK CVE-2022-4137 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies. 

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-22767 Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-22768 Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-22767 Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-22768 Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies 建议所有客户考虑 CVSS 基本分数以及任何相关的时间和环境分数,这可能会影响与特定安全漏洞相关的潜在严重程度。

受影响的产品和补救措施

Product Affected Versions Remediated Versions Link
Dell AppSync Versions prior to 4.6.1.0 Version 4.6.1.0 or later https://www.dell.com/support/home/product-support/product/appsync/drivers

 

Product Affected Versions Remediated Versions Link
Dell AppSync Versions prior to 4.6.1.0 Version 4.6.1.0 or later https://www.dell.com/support/home/product-support/product/appsync/drivers

 

修订历史记录

Revision DateDescription
1.02026-04-01Initial Release
2.02026-04-08Updated Affected versions

 

确认

CVE-2026-22768: Dell would like to thank Marius Gabriel Mihai for reporting this issue. 

CVE-2026-22767: Dell would like to thank falconCorrup for reporting this issue.  

相关信息

受影响的产品

AppSync, AppSync
文章属性
文章编号: 000446965
文章类型: Dell Security Advisory
上次修改时间: 07 4月 2026
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。