Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

DSA-2022-348: Dell Data Protection Central Security Update for Proprietary Code Vulnerability

Summary: Dell Data Protection Central remediation is available for Host Header Injection vulnerability that may be exploited by malicious users to compromise the affected system.

This article applies to   This article does not apply to 

Impact

Medium

Details

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-45102 Dell Data Protection Central versions 19.1 through 19.7 contain a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary 'Host' header values to poison a web cache or trigger redirections.  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-45102 Dell Data Protection Central versions 19.1 through 19.7 contain a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary 'Host' header values to poison a web cache or trigger redirections.  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Updated Versions Link to Update
Dell Data Protection Central 19.1 19.8 To upgrade your Dell Data Protection Central system, see Dell KB article 34881: Data Protection Central: How to Install the Data Protection Central operating system Update for installation instructions.

See the latest 'Data Protection Central OS Update' file in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/drivers.

See the latest 'Data Protection Central OS Updates Release Notes' in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/docs.
19.2 19.8
19.3 19.8
19.4 19.8
19.5 19.8
19.6 19.8
19.7 19.8
PowerProtect DP Series Appliance (Integration Data Protection Appliance) 2.5 2.7.x To upgrade your PowerProtect DP Series Appliance Dell Data Protection Central component, see Dell KB article 34881: Data Protection Central: How to Install the Data Protection Central operating system Update for installation instructions.

See the latest 'Data Protection Central OS Update' file in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/drivers.

See the latest 'Data Protection Central OS Updates Release Notes' in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/docs.
2.6.x 2.7.x
2.7.x 2.7.x
 
 
NOTE: For PowerProtect DP Series Appliance (Integration Data Protection Appliance), the appliance should first be upgraded to any 2.7.x version (version 2.7.2 is preferred) and then the previously mentioned Data Protection Central patch should be applied.
Product Affected Versions Updated Versions Link to Update
Dell Data Protection Central 19.1 19.8 To upgrade your Dell Data Protection Central system, see Dell KB article 34881: Data Protection Central: How to Install the Data Protection Central operating system Update for installation instructions.

See the latest 'Data Protection Central OS Update' file in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/drivers.

See the latest 'Data Protection Central OS Updates Release Notes' in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/docs.
19.2 19.8
19.3 19.8
19.4 19.8
19.5 19.8
19.6 19.8
19.7 19.8
PowerProtect DP Series Appliance (Integration Data Protection Appliance) 2.5 2.7.x To upgrade your PowerProtect DP Series Appliance Dell Data Protection Central component, see Dell KB article 34881: Data Protection Central: How to Install the Data Protection Central operating system Update for installation instructions.

See the latest 'Data Protection Central OS Update' file in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/drivers.

See the latest 'Data Protection Central OS Updates Release Notes' in https://www.dell.com/support/home/en-us/product-support/product/data-protection-central/docs.
2.6.x 2.7.x
2.7.x 2.7.x
 
 
NOTE: For PowerProtect DP Series Appliance (Integration Data Protection Appliance), the appliance should first be upgraded to any 2.7.x version (version 2.7.2 is preferred) and then the previously mentioned Data Protection Central patch should be applied.

Revision History

RevisionDateDescription
1.02022-12-15Initial Release

Related Information

Affected Products

PowerProtect Data Protection Appliance, Data Protection Central, PowerProtect Data Protection Software

Products

Product Security Information
Article Properties
Article Number: 000206329
Article Type: Dell Security Advisory
Last Modified: 15 Dec 2022
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.
Article Properties
Article Number: 000206329
Article Type: Dell Security Advisory
Last Modified: 15 Dec 2022
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.