Passer au contenu principal
  • Passer des commandes rapidement et facilement
  • Afficher les commandes et suivre l’état de votre expédition
  • Profitez de récompenses et de remises réservées aux membres
  • Créez et accédez à une liste de vos produits

DSA-2021-293: Dell PowerFlex Appliance Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105)

Résumé: Dell PowerFlex Appliance remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

Cet article concerne   Cet article ne concerne pas 

Impact

Critical

Détails

Third-party Component CVEs More information
Apache Log4j
 
CVE-2021-44228
CVE-2021-45046
CVE-2021-45105
Apache Log4j Remote Code Execution
 
Third-party Component CVEs More information
Apache Log4j
 
CVE-2021-44228
CVE-2021-45046
CVE-2021-45105
Apache Log4j Remote Code Execution
 
Dell Technologies recommande à tous les clients de prendre en compte à la fois le score de base CVSS et les scores temporels et environnementaux pertinents qui peuvent avoir un impact sur la gravité potentielle associée à une faille de sécurité donnée.

Produits concernés et mesure corrective

Affected Products and Remediation
CVEs Product Affected Versions Updated Versions Link to Update
CVE-2021-4228 
CVE-2021-45046
 
CVE-2021-45105
 
PowerFlex Appliance
 
 
Versions before Intelligent Catalog 38_356_00_r10
 
 
Intelligent_Catalog_38_356_01_r1 For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
 
 Versions before Intelligent Catalog 38_362_00_r7 Intelligent_Catalog_38_362_01_r1





Affected Components in the Product
Component Affected Versions Updated Versions Link to update
Dell PowerFlex Presentation Server 3.5, 3.5.1, 3.5.1.1, 3.5.1.2, 3.5.1.3, 3.5.1.4 3.6, 3.6.0.1, and 3.6.0.2 Versions 3.6.0.3 and 3.5.1.5 PowerFlex 3.6.0.3 build 107 Complete Software 
 
 
PowerFlex 3.5.1.5 Build 105 Complete Software Download
 
DSA-2021-272
Dell PowerFlex Manager 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, and 3.8.0 Version 3.8.0 (Build Number 3.8.0-8187) For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
VMware vCenter Server Appliance 6.5, 6.7, and 7.0 VMware-VCSA-all-6.5.0-19261680 (6.5 U3s)

VMware-VCSA-all-6.7 Update 3q (6.7.0 Build19300125

VMware-VCSA-all-7.0 Update 3c Build 19234570
For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers

Affected Products and Remediation
CVEs Product Affected Versions Updated Versions Link to Update
CVE-2021-4228 
CVE-2021-45046
 
CVE-2021-45105
 
PowerFlex Appliance
 
 
Versions before Intelligent Catalog 38_356_00_r10
 
 
Intelligent_Catalog_38_356_01_r1 For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
 
 Versions before Intelligent Catalog 38_362_00_r7 Intelligent_Catalog_38_362_01_r1





Affected Components in the Product
Component Affected Versions Updated Versions Link to update
Dell PowerFlex Presentation Server 3.5, 3.5.1, 3.5.1.1, 3.5.1.2, 3.5.1.3, 3.5.1.4 3.6, 3.6.0.1, and 3.6.0.2 Versions 3.6.0.3 and 3.5.1.5 PowerFlex 3.6.0.3 build 107 Complete Software 
 
 
PowerFlex 3.5.1.5 Build 105 Complete Software Download
 
DSA-2021-272
Dell PowerFlex Manager 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, 3.7.1, 3.7.2, and 3.8.0 Version 3.8.0 (Build Number 3.8.0-8187) For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers
VMware vCenter Server Appliance 6.5, 6.7, and 7.0 VMware-VCSA-all-6.5.0-19261680 (6.5 U3s)

VMware-VCSA-all-6.7 Update 3q (6.7.0 Build19300125

VMware-VCSA-all-7.0 Update 3c Build 19234570
For IC downloads:
https://www.dell.com/support/home/product-support/product/vxflex-appliance-sw/drivers

Historique des révisions

RevisionDateDescription
1.02021-12-16Initial Release
1.12021-12-17Added VMware vCenter Server Appliance workaround KB article link.
1.22021-12-22Added CVE-2021-45105 and remediation guidance
1.32022-01-10Added new ZIP with Log4j 2.17.1 remediation
2.02022-02-09Minor update - Workarounds and Mitigations - PowerFlex Manager section
3.02022-02-25Updated Affected Products and Remediation section, added links to update
4.02022-06-01updated VMware vCenter remediation

Informations connexes

Produits concernés

PowerFlex Appliance, PowerFlex appliance R650, PowerFlex appliance R6525, Powerflex appliance R750, Product Security Information, PowerFlex Software, PowerFlex appliance R640, PowerFlex appliance R740XD, PowerFlex appliance R840