DSA-2021-311: Dell EMC XC Series and Core Appliance Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105)
Résumé:
Dell EMC XC Series and Core Appliance remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the
affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability.
...
Sélectionnez un produit pour vérifier la pertinence de l’article
Cet article concerne Cet article ne concerne pasCet article n’est associé à aucun produit spécifique.Toutes les versions du produit ne sont pas identifiées dans cet article.
Dell Technologies recommande à tous les clients de prendre en compte à la fois le score de base CVSS et les scores temporels et environnementaux pertinents qui peuvent avoir un impact sur la gravité potentielle associée à une faille de sécurité donnée.
Produits concernés et mesure corrective
The table below shows the affected products and components impacted for the Dell EMC XC Series and Core Appliances.
Product
Affected Versions
Updated Versions
Link to Update
Nutanix AOS 6.0 STS (Short Term Support) Branch only
STS versions before 6.0.2.4
6.0.2.4
Patched in AOS 6.0.2.4, available from the Nutanix Support Portal (https://my.nutanix.com [Nutanix login required])
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
NOTE: To determine if additional features and software purchased directly from Nutanix are affected, see Nutanix Advisory: Nutanix Security Advisory #0023.
Dell EMC PowerTools (PTAgent) and iDRAC Service Module (iSM) software components that are included with XC Series and Core Appliances are unaffected.
The table below shows the affected products and components impacted for the Dell EMC XC Series and Core Appliances.
Product
Affected Versions
Updated Versions
Link to Update
Nutanix AOS 6.0 STS (Short Term Support) Branch only
STS versions before 6.0.2.4
6.0.2.4
Patched in AOS 6.0.2.4, available from the Nutanix Support Portal (https://my.nutanix.com [Nutanix login required])
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
NOTE: To determine if additional features and software purchased directly from Nutanix are affected, see Nutanix Advisory: Nutanix Security Advisory #0023.
Dell EMC PowerTools (PTAgent) and iDRAC Service Module (iSM) software components that are included with XC Series and Core Appliances are unaffected.
Solutions de contournement et mesures d’atténuation