DSA-2024-412: Security Update for Dell ECS 3.8.1.2 Multiple Third-Party Component Vulnerabilities

Sommaire: Dell ECS remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Cet article s’applique à Cet article ne s’applique pas à Cet article n’est lié à aucun produit spécifique. Toutes les versions de produits ne sont pas identifiées dans cet article.

Impact

High

Détails

Third-Party Component CVEs More Information
bind CVE-2023-4408, CVE-2023-50868 See NVD link below for Individual scores for each CVE.
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
Jasper CVE-2024-31744 https://nvd.nist.gov/vuln/detail/CVE-2024-31744This hyperlink is taking you to a website outside of Dell Technologies.
krb5 CVE-2024-26458, CVE-2024-26461 See NVD link below for Individual scores for each CVE.
https://nvd.nist.govThis hyperlink is taking you to a website outside of Dell Technologies.
less CVE-2024-32487 https://nvd.nist.gov/vuln/detail/CVE-2024-32487This hyperlink is taking you to a website outside of Dell Technologies.
libpython CVE-2023-52425 https://nvd.nist.gov/vuln/detail/CVE-2023-52425This hyperlink is taking you to a website outside of Dell Technologies.
python3 CVE-2024-0450 https://nvd.nist.gov/vuln/detail/CVE-2024-0450This hyperlink is taking you to a website outside of Dell Technologies.
python-idna CVE-2024-3651 https://nvd.nist.gov/vuln/detail/CVE-2024-3651This hyperlink is taking you to a website outside of Dell Technologies.
python-requests CVE-2024-35195 https://nvd.nist.gov/vuln/detail/CVE-2024-35195This hyperlink is taking you to a website outside of Dell Technologies.
util-linux CVE-2024-28085 https://nvd.nist.gov/vuln/detail/CVE-2024-28085This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommande à tous ses clients de tenir compte à la fois du score de base CVSS et de tous les scores temporels et environnementaux pertinents qui pourraient avoir une incidence sur la gravité potentielle associée à une vulnérabilité de sécurité particulière.

Produits touchés et correction

Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.2 Version 3.8.1.2 https://www.dell.com/support/incidents-online/contactus/dynamic
Product Affected Versions Remediated Versions Link
ECS Versions prior to 3.8.1.2 Version 3.8.1.2 https://www.dell.com/support/incidents-online/contactus/dynamic
Note:Dell Technologies recommends all customers have their ECS systems upgraded at the earliest opportunity by opening an Operating Environment Upgrade Service Request.

Historique de révision

RevisionDateDescription
1.02024-09-30Initial Release
2.02024-10-01Updated for enhanced presentation with no changes to content.
3.02021-10-03Updated for enhanced presentation with no changes to content.

Renseignements connexes

Produits touchés

ECS, ECS Appliance, ECS Appliance Hardware Series, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption
Propriétés de l’article
Numéro d’article: 000230678
Type d’article: Dell Security Advisory
Dernière modification: 03 oct. 2024
Obtenez des réponses à vos questions auprès d’autre utilisateurs de Dell
Services de soutien
Vérifiez si votre appareil est couvert par les services de soutien.