Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products

DSA-2021-196: Dell EMC VxRail Appliance Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell EMC VxRail Appliance remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected systems.

This article applies to   This article does not apply to 

Impact

Critical

Details

Third-Party Component CVEs Fixed in release: More information
vCenter Server 7.0
 
CVE-2021-22011
CVE-2021-22018
7.0.241 Severity: High, see VMSA-2021-0020
vCenter Server 6.7 CVE-2021-22005 4.7.536 Severity: Critical, see VMSA-2021-0020
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22006
CVE-2021-22007
CVE-2021-22008
CVE-2021-22009
CVE-2021-22010
CVE-2021-22011
CVE-2021-22014
CVE-2021-22015
CVE-2021-22016
CVE-2021-22017
CVE-2021-22019
CVE-2021-22020
4.7.536 Severity: High, see VMSA-2021-0020
vCenter Server 6.5
 
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22008
CVE-2021-22009
CVE-2021-22011
CVE-2021-22012
CVE-2021-22013
CVE-2021-22014
CVE-2021-22015
CVE-2021-22017
CVE-2021-22019
4.5.463 Severity: High, see VMSA-2021-0020
Third-Party Component CVEs Fixed in release: More information
vCenter Server 7.0
 
CVE-2021-22011
CVE-2021-22018
7.0.241 Severity: High, see VMSA-2021-0020
vCenter Server 6.7 CVE-2021-22005 4.7.536 Severity: Critical, see VMSA-2021-0020
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22006
CVE-2021-22007
CVE-2021-22008
CVE-2021-22009
CVE-2021-22010
CVE-2021-22011
CVE-2021-22014
CVE-2021-22015
CVE-2021-22016
CVE-2021-22017
CVE-2021-22019
CVE-2021-22020
4.7.536 Severity: High, see VMSA-2021-0020
vCenter Server 6.5
 
CVE-2021-21991
CVE-2021-21992
CVE-2021-21993
CVE-2021-22008
CVE-2021-22009
CVE-2021-22011
CVE-2021-22012
CVE-2021-22013
CVE-2021-22014
CVE-2021-22015
CVE-2021-22017
CVE-2021-22019
4.5.463 Severity: High, see VMSA-2021-0020
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs Addressed Product Affected Versions Updated Versions
See above table Dell EMC VxRail Appliance 7.0.x versions before 7.0.241
4.7.x versions before 4.7.536
4.5.x versions before 4.5.463
 7.0.241
 4.7.536
 4.5.463
CVEs Addressed Product Affected Versions Updated Versions
See above table Dell EMC VxRail Appliance 7.0.x versions before 7.0.241
4.7.x versions before 4.7.536
4.5.x versions before 4.5.463
 7.0.241
 4.7.536
 4.5.463

Revision History

RevisionDateDescription
1.02021-09-23Initial Release
1.12021-10-04Updated to remove CVEs that were fixed in release 7.0.240
1.22021-11-17Updated to clarify affected version numbers

Related Information

Affected Products

VxRail, Product Security Information