Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

DSA-2020-028: Dell EMC VCF over VxRail Security Update for VMware vCenter Server Appliance e File-Based Backup and Restore functions Sensitive information disclosure vulnerabilities

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Summary:   
VMware vCenter Server Appliance e File-Based Backup and Restore functions Sensitive information disclosure vulnerabilities in Dell EMC VCF over VxRail, requires a security update to address multiple vulnerabilities.

VMware vCenter Server Appliance is an embedded management platform used in Dell EMC VCF over VxRail.

VMware vCenter Server Appliance has been updated to address the following vulnerabilities:   

  • CVE-2019-5537
    CVE-2019-5538

Refer to the VMware Security Advisory for more information.

See NVD (http://nvd.nist.gov/) for individual scores for each CVE

VMware vCenter Server Appliance is an embedded management platform used in Dell EMC VCF over VxRail.

VMware vCenter Server Appliance has been updated to address the following vulnerabilities:   

  • CVE-2019-5537
    CVE-2019-5538

Refer to the VMware Security Advisory for more information.

See NVD (http://nvd.nist.gov/) for individual scores for each CVE

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected Products:   
VCF over VxRail versions prior to 3.9.1

Remediation:
The following Dell EMC VCF over VxRail release addresses these vulnerabilities:   

  • VCF over VxRail 3.9.1

For Dell EMC VCF over VxRail 3.9.1 and later, the security update is contained in the release VCF over VxRail 3.9.1

Dell EMC recommends all customers upgrade at the earliest opportunity.

https://docs.vmware.com/en/VMware-Cloud-Foundation/3.9.1/rn/vmware-cloud-foundation-on-dell-emc-vxrail-16-release-notes.html



Affected Products:   
VCF over VxRail versions prior to 3.9.1

Remediation:
The following Dell EMC VCF over VxRail release addresses these vulnerabilities:   

  • VCF over VxRail 3.9.1

For Dell EMC VCF over VxRail 3.9.1 and later, the security update is contained in the release VCF over VxRail 3.9.1

Dell EMC recommends all customers upgrade at the earliest opportunity.

https://docs.vmware.com/en/VMware-Cloud-Foundation/3.9.1/rn/vmware-cloud-foundation-on-dell-emc-vxrail-16-release-notes.html



Related Information

Affected Products

VxRack SDDC

Products

CloudArray Virtual Edition for VxRail Appliance, Pivotal Ready Architecture, VMWare Cloud on Dell EMC VxRail E560F, VMWare Cloud on Dell EMC VxRail E560N, VMware vCenter Server, VxRack SDDC, VxRail 460 and 470 Nodes, VxRail Appliance Family , VxRail Appliance Series, VxRail G410, VxRail G Series Nodes, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560 VCF, VxRail E560F, VxRail E560F VCF, VxRail E560N, VxRail E560N VCF, VxRail G560, VxRail G560 VCF, VxRail G560F, VxRail G560F VCF, VxRail Gen2 Hardware, VxRail P Series Nodes, VxRail P470, VxRail P570, VxRail P570 VCF, VxRail P570F, VxRail P570F VCF, VxRail P580N VCF, VxRail S Series Nodes, VxRail S470, VxRail S570 VCF, VxRail Software, VxRail V Series Nodes, VxRail V470, VxRail V570, VxRail V570 VCF, VxRail V570F, VxRail V570F VCF ...
Article Properties
Article Number: 000153592
Article Type: Dell Security Advisory
Last Modified: 22 May 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.