Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products

DSA-2020-216: PowerFlex Rack Security Update for Multiple Third-Party Component Vulnerabilities

Summary: DSA-2020-216: PowerFlex Rack Security Update for Multiple Third-Party Component Vulnerabilities

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Summary:
Multiple components within Dell EMC PowerFlex Rack require a security update to address various vulnerabilities.

Third-party Component CVE(s) More information
iDRAC version 4.20.20.20 CVE-2020-5366 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
VMware ESXi 6.5 EP 20 16389870 (Build 16389870) and ESXi 6.7 EP 15 Build Number 16316930 CVE-2020-3967 VMSA-2020-0011
VMSA-2020-0012
VMSA-2020-0014

 
CVE-2020-3968
CVE-2020-3966
CVE-2020-3965
CVE-2020-3963
CVE-2020-3964
CVE-2020-3960
CVE-2020-3959
GRUB Bootloader Vulnerability CVE-2020-10713 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
Third-party Component CVE(s) More information
iDRAC version 4.20.20.20 CVE-2020-5366 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
VMware ESXi 6.5 EP 20 16389870 (Build 16389870) and ESXi 6.7 EP 15 Build Number 16316930 CVE-2020-3967 VMSA-2020-0011
VMSA-2020-0012
VMSA-2020-0014

 
CVE-2020-3968
CVE-2020-3966
CVE-2020-3965
CVE-2020-3963
CVE-2020-3964
CVE-2020-3960
CVE-2020-3959
GRUB Bootloader Vulnerability CVE-2020-10713 See NVD (http://nvd.nist.gov/) for individual scores for each CVE
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected Products:
Dell EMC PowerFlex Rack versions prior to 3.3.8.1
Dell EMC PowerFlex Rack versions prior to 3.4.3.1
Dell EMC PowerFlex Rack versions prior to 3.5.3.1

Resolution:
The following Dell EMC PowerFlex Rack releases contain a resolution to these vulnerabilities:
  • Dell EMC PowerFlex Rack version 3.3.8.1
  • Dell EMC PowerFlex Rack version 3.4.3.1
  • Dell EMC PowerFlex Rack version 3.5.3.1

Dell EMC recommends all customers upgrade at the earliest opportunity.
For RCM release information: https://cpsdocs.dellemc.com/rcm/#/home.
For RCM download: https://vce.flexnetoperations.com/control/vcec/product?plneID=740417

Affected Products:
Dell EMC PowerFlex Rack versions prior to 3.3.8.1
Dell EMC PowerFlex Rack versions prior to 3.4.3.1
Dell EMC PowerFlex Rack versions prior to 3.5.3.1

Resolution:
The following Dell EMC PowerFlex Rack releases contain a resolution to these vulnerabilities:
  • Dell EMC PowerFlex Rack version 3.3.8.1
  • Dell EMC PowerFlex Rack version 3.4.3.1
  • Dell EMC PowerFlex Rack version 3.5.3.1

Dell EMC recommends all customers upgrade at the earliest opportunity.
For RCM release information: https://cpsdocs.dellemc.com/rcm/#/home.
For RCM download: https://vce.flexnetoperations.com/control/vcec/product?plneID=740417

Related Information

Affected Products

VxFlex Product Family

Products

Product Security Information, VxFlex Product Family
Article Properties
Article Number: 000001679
Article Type: Dell Security Advisory
Last Modified: 10 Apr 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.