Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

Article Number: 000204809


DSA-2022-290: Dell XtremIO X2 Security Update for a XMS GUI Vulnerability

Summary: XtremIO X2 remediation is available for XMS GUI that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2022-34453 Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2022-34453 Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default. 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product  Affected Version(s)  Updated Version(s)  Link to Update 
XtremIO X2  All releases prior to 6.4.1-11 6.4.1-11 Support for XtremIO X2 | Drivers & Downloads | Dell US
Product  Affected Version(s)  Updated Version(s)  Link to Update 
XtremIO X2  All releases prior to 6.4.1-11 6.4.1-11 Support for XtremIO X2 | Drivers & Downloads | Dell US

Revision History

Revision Date Description 
1.0 2022-11-1 Initial Release
1.22022-11-14Corrected “Affected Products and Remediation” section. Updated “Workaround and Mitigations” section.
2.02023-7-18Updated “Proprietary Code” section and “Affected Products and Remediation” section: added Remediated details.

Related Information


Article Properties


Affected Product

XtremIO, Product Security Information, XtremIO Family, XtremIO X2

Last Published Date

26 Jul 2023

Article Type

Dell Security Advisory