Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000153604


DSA-2020-136: Dell EMC VxRail Appliance Improper Authentication Vulnerability

Summary: Dell EMC VxRail Appliance contains remediation for a security vulnerability that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

Medium

Details

NA

Dell EMC VxRail versions 4.7.410 and 4.7.411 and 4.7.510 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

CVE-2020-5368
5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Dell EMC VxRail versions 4.7.410 and 4.7.411 and 4.7.510 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

CVE-2020-5368
5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Affected products:   

  • Dell EMC VxRail Appliance 4.7.410

  • Dell EMC VxRail Appliance 4.7.411

  • Dell EMC VxRail Appliance 4.7.510


Remediation:
The following Dell EMC VxRail Appliance release addresses this vulnerability:    
  • Dell EMC VxRail Appliance 4.7.511

Dell EMC recommends all customers upgrade at the earliest opportunity.

Affected products:   

  • Dell EMC VxRail Appliance 4.7.410

  • Dell EMC VxRail Appliance 4.7.411

  • Dell EMC VxRail Appliance 4.7.510


Remediation:
The following Dell EMC VxRail Appliance release addresses this vulnerability:    
  • Dell EMC VxRail Appliance 4.7.511

Dell EMC recommends all customers upgrade at the earliest opportunity.

Acknowledgements

Dell EMC would like to thank Florian Hauser (Code White) for reporting this vulnerability.

Related Information


Article Properties


Affected Product
Pivotal Ready Architecture, Product Security Information, VMWare Cloud on Dell EMC VxRail E560F, VMWare Cloud on Dell EMC VxRail E560N, VxRail 460 and 470 Nodes, VxRail Appliance Family, VxRail Appliance Series, VxRail G Series Nodes , VxRail D Series Nodes, VxRail D560F, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560 VCF, VxRail E560F VCF, VxRail E560N, VxRail E560N VCF, VxRail E665F, VxRail E665N, VxRail G560, VxRail G560F, VxRail Gen2 Hardware, VxRail P Series Nodes, VxRail P470, VxRail P570, VxRail P570 VCF, VxRail P570F, VxRail P570F VCF, VxRail P580N, VxRail P580N VCF, VxRail S Series Nodes, VxRail S470, VxRail S570, VxRail S570 VCF, VxRail Software, VxRail V Series Nodes, VxRail V470, VxRail V570, VxRail V570 VCF, VxRail V570F, VxRail V570F VCF ...
Last Published Date

19 Nov 2021

Article Type

Dell Security Advisory