DSA-2024-487: Security Update for Cloud Tiering Appliance/VE Multiple Third-Party Component Vulnerabilities.

摘要: Dell Cloud Tiering Appliance/VE remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

本文章適用於 本文章不適用於 本文無關於任何特定產品。 本文未識別所有產品版本。

影響

Critical

詳細資料

Third-party Component

CVEs

More Information

openssl-1_1 

CVE-2024-5535, CVE-2023-50782 

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

postgresql16 

CVE-2024-7348 

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

kernel-default 

CVE-2022-0854, CVE-2022-20368, CVE-2022-28748, CVE-2022-2964, CVE-2022-48686, CVE-2022-48791, CVE-2022-48802, CVE-2022-48805, CVE-2022-48839, CVE-2022-48853, CVE-2022-48872, CVE-2022-48873, CVE-2022-48901, CVE-2022-48912, CVE-2022-48919, CVE-2022-48925, CVE-2023-1582, CVE-2023-2176,  CVE-2023-52854, CVE-2024-26583, CVE-2024-26584, CVE-2024-26800, CVE-2024-41011, CVE-2024-41062, CVE-2024-42077, CVE-2024-42232, CVE-2024-42271, CVE-2024-43861, CVE-2024-43882, CVE-2024-43883, CVE-2024-44947, CVE-2021-47069, CVE-2022-48911, CVE-2022-48945, CVE-2024-36971, CVE-2024-41087, CVE-2024-44946, CVE-2024-45003, CVE-2024-45021, CVE-2024-46695, CVE-2024-46774

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Python-setuptools 

CVE-2024-6345

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

xen-libs 

CVE-2024-31145, CVE-2024-31146 

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

python3  

CVE-2024-6923, CVE-2024-7592 

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

kernel-firmware 

CVE-2023-31315 

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

java-11-openjdk

CVE-2024-21208, CVE-2024-21210, CVE-2024-21217, CVE-2024-21235 

See NVD link below for individual scores for each CVE. 

http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies 建議所有客戶不僅要參考 CVSS 基本分數,也要將可能會影響與特定安全漏洞相關之潛在嚴重性的所有相關暫時和環境分數納入考量。

受影響的產品與補救措施

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

Cloud Tiering Appliance

CTA and CTA-HA 

Versions prior to 13.2.0.2.32 

Version 13.2.0.2.32 or later 

https://www.dell.com/support/home/product-support/product/cloud-tiering-applianceve/drivers 

Cloud Tiering Appliance/VE

CTA/VE and CTA-HA/VE 

Versions prior to 13.2.0.2.32 

Version 13.2.0.2.32 or later 

https://www.dell.com/support/home/product-support/product/cloud-tiering-applianceve/drivers 

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

Cloud Tiering Appliance

CTA and CTA-HA 

Versions prior to 13.2.0.2.32 

Version 13.2.0.2.32 or later 

https://www.dell.com/support/home/product-support/product/cloud-tiering-applianceve/drivers 

Cloud Tiering Appliance/VE

CTA/VE and CTA-HA/VE 

Versions prior to 13.2.0.2.32 

Version 13.2.0.2.32 or later 

https://www.dell.com/support/home/product-support/product/cloud-tiering-applianceve/drivers 

修訂歷史記錄

Revision

Date

Description

1.0

2024-12-09

Initial Release

相關資訊

受影響的產品

Cloud Tiering Appliance/VE
文章屬性
文章編號: 000258232
文章類型: Dell Security Advisory
上次修改時間: 09 9月 2025
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。