Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

DSA-2021-197: Dell EMC PowerFlex Appliance Security Update for Multiple Third-Party Component Vulnerabilities

Summary: Dell EMC PowerFlex Appliance remediation for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

This article applies to   This article does not apply to 

Impact

Critical

Details

Component CVE(s) CVSS Base
Score
More information
VMware ESXi CVE-2021-21994 7.0 VMSA-2021-0014
CVE-2021-21995 5.3
vCenter Server CVE-2021-22005 9.8 VMSA-2021-0020
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
Note:
  • This RCM release has fixes only for vSphere 7.0x.
  • Fixes for vSphere 6.5 and 6.7 will be in the future release.
  • See “Workaround” section at the end of this article.
CVE-2021-21991 4.3-8.8
CVE-2021-21992
CVE-2021-21993
CVE-2021-22006
CVE-2021-22007
CVE-2021-22008
CVE-2021-22009
CVE-2021-22010
CVE-2021-22014
CVE-2021-22015
CVE-2021-22019
CVE-2021-22020
iDRAC CVE-2021-21581 6.5 DSA-2021-133
DSA-2021-177
CVE-2021-21580 4.3
CVE-2021-21579 6.1
CVE-2021-21578 6.1
CVE-2021-21577 6.1
CVE-2021-21576 6.1
CVE-2021-36299 5.9
CVE-2021-36300 6.5
CVE-2021-36301 7.1
CVE-2021-20235 7.1
PowerFlex Manager CVE-1999-0519 7.5  
CVE-1999-0520 6.4
CVE-1999-0517 7.5
Component CVE(s) CVSS Base
Score
More information
VMware ESXi CVE-2021-21994 7.0 VMSA-2021-0014
CVE-2021-21995 5.3
vCenter Server CVE-2021-22005 9.8 VMSA-2021-0020
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
Note:
  • This RCM release has fixes only for vSphere 7.0x.
  • Fixes for vSphere 6.5 and 6.7 will be in the future release.
  • See “Workaround” section at the end of this article.
CVE-2021-21991 4.3-8.8
CVE-2021-21992
CVE-2021-21993
CVE-2021-22006
CVE-2021-22007
CVE-2021-22008
CVE-2021-22009
CVE-2021-22010
CVE-2021-22014
CVE-2021-22015
CVE-2021-22019
CVE-2021-22020
iDRAC CVE-2021-21581 6.5 DSA-2021-133
DSA-2021-177
CVE-2021-21580 4.3
CVE-2021-21579 6.1
CVE-2021-21578 6.1
CVE-2021-21577 6.1
CVE-2021-21576 6.1
CVE-2021-36299 5.9
CVE-2021-36300 6.5
CVE-2021-36301 7.1
CVE-2021-20235 7.1
PowerFlex Manager CVE-1999-0519 7.5  
CVE-1999-0520 6.4
CVE-1999-0517 7.5
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-36301 PowerFlex Appliance Versions before Intelligent Catalog 37.355.01.r16


Versions before Intelligent Catalog 37.361.01.r14
Intelligent Catalog 37.355.01.r16


Intelligent Catalog 37.361.01.r14
For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
CVE-2021-36300
CVE-2021-36299
CVE-2021-22020
CVE-2021-22019
CVE-2021-22015
CVE-2021-22014
CVE-2021-22010
CVE-2021-22009
CVE-2021-22008
CVE-2021-22007
CVE-2021-22006
CVE-2021-22005
CVE-2021-21995
CVE-2021-21994
CVE-2021-21993
CVE-2021-21992
CVE-2021-21991
CVE-2021-21581
CVE-2021-21580
CVE-2021-21579
CVE-2021-21578
CVE-2021-21577
CVE-2021-21576
CVE-2021-20235
CVE-1999-0520
CVE-1999-0519
CVE-1999-0517
CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2021-36301 PowerFlex Appliance Versions before Intelligent Catalog 37.355.01.r16


Versions before Intelligent Catalog 37.361.01.r14
Intelligent Catalog 37.355.01.r16


Intelligent Catalog 37.361.01.r14
For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
CVE-2021-36300
CVE-2021-36299
CVE-2021-22020
CVE-2021-22019
CVE-2021-22015
CVE-2021-22014
CVE-2021-22010
CVE-2021-22009
CVE-2021-22008
CVE-2021-22007
CVE-2021-22006
CVE-2021-22005
CVE-2021-21995
CVE-2021-21994
CVE-2021-21993
CVE-2021-21992
CVE-2021-21991
CVE-2021-21581
CVE-2021-21580
CVE-2021-21579
CVE-2021-21578
CVE-2021-21577
CVE-2021-21576
CVE-2021-20235
CVE-1999-0520
CVE-1999-0519
CVE-1999-0517

Workarounds & Mitigations

For CVE-2021-22005 under VMSA-2021-0020 (https://www.vmware.com/security/advisories/VMSA-2021-0020.html), refer to the following link for workarounds: https://kb.vmware.com/s/article/85717.

Revision History

RevisionDateDescription
1.02021-09-24Initial Release
2.02021-09-30Added VMware Security Advisory link, Workaround notes for vSphere 6.5 and 6.7, and Component CVSS Base Scores to Details section. Added Workaround links to Workarounds and Mitigations section.  

Related Information

Affected Products

PowerFlex Appliance, iDRAC8 with Lifecycle Controller version 2.80.80.80, iDRAC9 - 4.xx Series, iDRAC9 - 5.xx Series, Product Security Information, PowerFlex Software, VMware vCenter Server, PowerFlex appliance R640, PowerFlex appliance R740XD , PowerFlex appliance R840 ...
Article Properties
Article Number: 000191834
Article Type: Dell Security Advisory
Last Modified: 30 Sep 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.
Article Properties
Article Number: 000191834
Article Type: Dell Security Advisory
Last Modified: 30 Sep 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.