DSA-2023-195: Security Update Dell Streaming Data Platform

摘要: Dell Streaming Data Platform remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

本文章適用於 本文章不適用於 本文無關於任何特定產品。 本文未識別所有產品版本。

影響

Critical

詳細資料

Third-party Component CVEs More Information
com.fasterxml.jackson.core_jackson-databind CVE-2022-42003, CVE-2022-42004 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
com.google.protobuf_protobuf-java CVE-2021-22569, CVE-2022-3171 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
commons-net_commons-net CVE-2021-37533 https://nvd.nist.gov/vuln/detail/CVE-2021-37533 This hyperlink is taking you to a website outside of Dell Technologies. 
github.com/containerd/containerd CVE-2022-23471, CVE-2023-25153, CVE-2023-25173 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
github.com/opencontainers/runc CVE-2023-27561 https://nvd.nist.gov/vuln/detail/CVE-2023-27561 This hyperlink is taking you to a website outside of Dell Technologies. 
github.com/prometheus/exporter-toolkit CVE-2022-46146 https://nvd.nist.gov/vuln/detail/CVE-2022-46146 This hyperlink is taking you to a website outside of Dell Technologies. 
go CVE-2022-1705, CVE-2022-1962, CVE-2022-24675, CVE-2022-27664, CVE-2022-28131, CVE-2022-28327, CVE-2022-2879, CVE-2022-2880, CVE-2022-30580, CVE-2022-30630, CVE-2022-30631, CVE-2022-30632, CVE-2022-30633, CVE-2022-30635, CVE-2022-32148, CVE-2022-32189, CVE-2022-32190, CVE-2022-41715, CVE-2022-41716, CVE-2022-41717, CVE-2022-41723, CVE-2022-41724, CVE-2022-41725, CVE-2023-24532 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/crypto CVE-2021-43565, CVE-2022-27191 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/net CVE-2022-27664, CVE-2022-41721, CVE-2022-41723 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/sys CVE-2022-29526 https://nvd.nist.gov/vuln/detail/CVE-2022-29526 This hyperlink is taking you to a website outside of Dell Technologies. 
golang.org/x/text/language CVE-2022-32149 https://nvd.nist.gov/vuln/detail/CVE-2022-32149 This hyperlink is taking you to a website outside of Dell Technologies. 
helm.sh/helm/v3 CVE-2022-23524, CVE-2022-23525, CVE-2022-23526, CVE-2023-25165 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
http-cache-semantics CVE-2022-25881 https://nvd.nist.gov/vuln/detail/CVE-2022-25881 This hyperlink is taking you to a website outside of Dell Technologies. 
libcurl,curl CVE-2023-23914, CVE-2023-23915, CVE-2023-23916 See NVD link below for individual scores for each CVE.
https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
libgnutls30 CVE-2023-0361 https://nvd.nist.gov/vuln/detail/CVE-2023-0361 This hyperlink is taking you to a website outside of Dell Technologies. 
libcrypto1.1 CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
libcrypto3 CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
net-snmp-tools CVE-2022-44792, CVE-2022-44793 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
net-snmp-libs CVE-2022-44792, CVE-2022-44793 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
node CVE-2023-23918, CVE-2023-23920, CVE-2023-23936 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 
openssl CVE-2022-2097, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286 See NVD link below for individual scores for each CVE. https://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies. 

Dell Technologies 建議所有客戶不僅要參考 CVSS 基本分數,也要將可能會影響與特定安全漏洞相關之潛在嚴重性的所有相關暫時和環境分數納入考量。

受影響的產品與補救措施

Product Affected Versions Remediated Versions Link
Dell Streaming Data Platform Versions 1.1.x through 1.6.x  1.7.0 https://www.dell.com/support/home/en-us/product-support/product/streaming-data-platform/drivers
 
Product Affected Versions Remediated Versions Link
Dell Streaming Data Platform Versions 1.1.x through 1.6.x  1.7.0 https://www.dell.com/support/home/en-us/product-support/product/streaming-data-platform/drivers
 
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

修訂歷史記錄

RevisionDateDescription
1.02023-06-05Initial Release
2.02023-08-29Updated for enhanced presentation with no changes to content.

相關資訊

受影響的產品

Streaming Data Platform Family, Streaming Data Platform
文章屬性
文章編號: 000214599
文章類型: Dell Security Advisory
上次修改時間: 19 9月 2025
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。