Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000184493


DSA-2021-010: Dell ECS Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell ECS contains remediation for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Third-Party Component CVE(s) More information
Intel® Boot Guard Firmware CVE-2020-8705 INTEL-SA-00391
Intel® CSME, SPS Firmware CVE-2020-8755 INTEL-SA-00391
Oracle Java SE CVE-2020-14803 Oracle Critical Patch Update Advisory - October 2020
CVE-2020-14792
CVE-2020-14781
CVE-2020-14782
CVE-2020-14797
CVE-2020-14779
CVE-2020-14796
CVE-2020-14798
Sudo CVE-2021-3156 NVD - CVE-2021-3156
Third-Party Component CVE(s) More information
Intel® Boot Guard Firmware CVE-2020-8705 INTEL-SA-00391
Intel® CSME, SPS Firmware CVE-2020-8755 INTEL-SA-00391
Oracle Java SE CVE-2020-14803 Oracle Critical Patch Update Advisory - October 2020
CVE-2020-14792
CVE-2020-14781
CVE-2020-14782
CVE-2020-14797
CVE-2020-14779
CVE-2020-14796
CVE-2020-14798
Sudo CVE-2021-3156 NVD - CVE-2021-3156
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVE(s) Addressed Product Affected Version(s) Updated Version(s) Link to Update
CVE-2020-8705

CVE-2020-8755
EX300-server-firmware Firmware versions prior to version 1.10 version 1.10 Refer to DSA-2020-246 for specific firmware component.
EX500-server-firmware Firmware versions prior to version 1.4 version 1.4
EXF900-server-firmware Firmware versions prior to version 1.3 version 1.3
CVE-2020-8705 ECS Versions prior to 3.6.1 version 3.6.1 Link
CVE-2020-8755
CVE-2020-14803
CVE-2020-14792
CVE-2020-14781
CVE-2020-14782
CVE-2020-14797
CVE-2020-14779
CVE-2020-14796
CVE-2020-14798
CVE-2021-3156

NOTE: Customers should open an “Operating Environment Upgrade” Service Request with the ECS Remote Proactive team and reference this DSA number along with the desired remediation action from the below:      
  1. Upgrade to ECS 3.6.1
  2. Upgrade to ECS 3.6.1 + apply firmware bundle v1.10 (Ex300), firmware bundle v1.4 (EX500), or firmware bundle 1.3 (EXF900)
  3. Apply firmware bundle v1.10 (Ex300), or firmware bundle v1.4 (EX500), or firmware bundle 1.3 (EXF900)
CVE(s) Addressed Product Affected Version(s) Updated Version(s) Link to Update
CVE-2020-8705

CVE-2020-8755
EX300-server-firmware Firmware versions prior to version 1.10 version 1.10 Refer to DSA-2020-246 for specific firmware component.
EX500-server-firmware Firmware versions prior to version 1.4 version 1.4
EXF900-server-firmware Firmware versions prior to version 1.3 version 1.3
CVE-2020-8705 ECS Versions prior to 3.6.1 version 3.6.1 Link
CVE-2020-8755
CVE-2020-14803
CVE-2020-14792
CVE-2020-14781
CVE-2020-14782
CVE-2020-14797
CVE-2020-14779
CVE-2020-14796
CVE-2020-14798
CVE-2021-3156

NOTE: Customers should open an “Operating Environment Upgrade” Service Request with the ECS Remote Proactive team and reference this DSA number along with the desired remediation action from the below:      
  1. Upgrade to ECS 3.6.1
  2. Upgrade to ECS 3.6.1 + apply firmware bundle v1.10 (Ex300), firmware bundle v1.4 (EX500), or firmware bundle 1.3 (EXF900)
  3. Apply firmware bundle v1.10 (Ex300), or firmware bundle v1.4 (EX500), or firmware bundle 1.3 (EXF900)

Revision History

RevisionDateDescription
1.02021-03-23Initial Release

Related Information


Article Properties


Affected Product

ECS Appliance Hardware Gen3 EX300, ECS Appliance Hardware Gen3 EX500, ECS Appliance Hardware Gen3 EXF900, Product Security Information

Last Published Date

23 Mar 2021

Article Type

Dell Security Advisory