Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000218038


DSA-2023-331: Security Update for Dell EMC AppSync

Summary: Dell EMC AppSync remediation is available for Dell Embedded Service Enabler vulnerability that could be exploited by local malicious user to compromise the affected system

Article Content


Impact

High

Details

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2023-32458 Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during installation leading to a privilege escalation. 7.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2023-32458 Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during installation leading to a privilege escalation. 7.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Updated Version Link to Update  
Dell EMC AppSync Versions 4.4.0.0, 4.5.0.0 and 4.6.0.0 including Service Pack releases See Workaround and Mitigation AppSync 4.6 Installation and Configuration Guide (dell.com)

AppSync 4.5 Installation and Configuration Guide (dell.com)

Dell EMC AppSync 4.4 SP1 Installation and Configuration Guide
 
 
 
 
Product Affected Versions Updated Version Link to Update  
Dell EMC AppSync Versions 4.4.0.0, 4.5.0.0 and 4.6.0.0 including Service Pack releases See Workaround and Mitigation AppSync 4.6 Installation and Configuration Guide (dell.com)

AppSync 4.5 Installation and Configuration Guide (dell.com)

Dell EMC AppSync 4.4 SP1 Installation and Configuration Guide
 
 
 
 
To mitigate this vulnerability, the user must verify the below prerequisite: -

The installation path or directory targeted for AppSync server installation is empty before performing a fresh install.

Workarounds and Mitigations

CVE Workaround
CVE-2023-32458

To mitigate this vulnerability, the user must verify the below prerequisite: 

The installation path or directory targeted for AppSync server installation is empty before performing a fresh install.

AppSync 4.6.0.0 document: AppSync 4.6 Installation and Configuration Guide (dell.com)

AppSync 4.5.0.0 document: AppSync 4.5 Installation and Configuration Guide (dell.com)

AppSync 4.4.0.0 document: Dell EMC AppSync 4.4 SP1 Installation and Configuration Guide
 

Acknowledgements

Dell Technologies would like to thank Gee-netics for reporting this issue.
 

Revision History

RevisionDateDescription
1.02023-09-27Initial Release
2.02023-10-04Updated for enhanced presentation with no changes to content.
3.02023-12-04Updated the Workaround and Mitigation section for more clarity
4.02024-03-14Added details to Workaround and Mitigation section

Related Information


Article Properties


Last Published Date

14 Mar 2024

Article Type

Dell Security Advisory