Critical
Third-party Component | CVEs | More Information |
---|---|---|
Apache Shiro | CVE-2022-32532, CVE-2022-40664 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Babel | CVE-2021-42771 |
See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
binutils | CVE-2021-20294, CVE-2021-20284, CVE-2021-20197, CVE-2020-16590, CVE-2020-16591, CVE-2020-16592, CVE-2020-16593, CVE-2020-16599, CVE-2021-3487, CVE-2020-35448, CVE-2020-35493, CVE-2020-35496, CVE-2020-35507 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
bindutils | CVE-2022-38177, CVE-2022-38178, CVE-2022-2795 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Certifi | CVE-2022-23491 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
cryptography | CVE-2018-10903, CVE-2023-0286, CVE-2023-23931 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
com.google.code.gson | CVE-2022-25647 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Future | CVE-2022-40899 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
grub2 | CVE-2022-28735, CVE-2022-28736, CVE-2022-28737 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
io.netty | CVE-2022-24823, CVE-2022-41915, CVE-2022-41881 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
java-11-openjdk | CVE-2022-21541, CVE-2022-34169, CVE-2022-21540, CVE-2022-21476, CVE-2022-21443, CVE-2022-21434, CVE-2022-21496, CVE-2022-21426, CVE-2021-35603, CVE-2021-35586, CVE-2021-35567, CVE-2021-35565, CVE-2021-35564, CVE-2021-35561, CVE-2021-35556, CVE-2021-35550, CVE-2021-35559, CVE-2021-35578, CVE-2021-2388, CVE-2021-2369, CVE-2021-2341 | July 2022 CPU, April 2022 CPU, October 2021 CPU, July 2021 CPU |
kernel | CVE-2022-36280, CVE-2022-38096, CVE-2023-0045, CVE-2023-0590, CVE-2023-0597, CVE-2023-1118, CVE-2023-22995, CVE-2023-23000, CVE-2023-23006, CVE-2023-23559, CVE-2023-26545 | SUSE-SU-2023:0778-1 |
krb5 | CVE-2022-42898 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libexpat1 | CVE-2022-40674, CVE-2022-43680 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libfreebl3 | CVE-2022-31741, CVE-2022-23491, CVE-2022-3479 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libgnutls30 | CVE-2021-4209, CVE-2022-2509 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libharfbuzz0 | CVE-2022-33068 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libonig4 | CVE-2019-13224 CVE-2019-19246, CVE-2019-19204, CVE-2019-19203, CVE-2019-16163 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libpcre2-8-0 | CVE-2019-20454, CVE-2022-1587 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libpixman-1-0 | CVE-2022-44638 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libpq5 | CVE-2022-2625, CVE-2022-41862 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libprotobuf-lite20 | CVE-2022-3171 CVE-2022-1941 CVE-2021-22570 CVE-2021-22569 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libksba8 | CVE-2022-47629, CVE-2022-3515 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libsasl2 | CVE-2019-19906 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libsoftokn3, libsoftokn3-hmac | CVE-2022-3479, CVE-2022-23491, CVE-2022-31741 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libtasn1 | CVE-2021-46848 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libtirpc3, libtirpc-netconfig | CVE-2021-46828 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libxml2-2 | CVE-2016-3709, CVE-2022-40303, CVE-2022-40304 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libXpm4 | CVE-2022-4883 CVE-2022-46285 CVE-2022-44617 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libxslt1, libxslt-tools | CVE-2021-30560 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
libz1 | CVE-2022-37434 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
mozilla-nss, mozilla-nss-certs | CVE-2022-31741, CVE-2022-23491, CVE-2022-3479 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
multipath-tools | CVE-2022-41973, CVE-2022-41974 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
NuProcess | CVE-2022-39243 |
See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
OpenSSL | CVE-2022-2097, CVE-2022-1292, CVE-2022-2068, CVE-2023-0286, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Oxygen XML WebHelp | CVE-2021-46827 |
See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
paramiko | CVE-2018-1000805, CVE-2022-24302 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
postgresql12 | CVE-2022-41862 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
psutil | CVE-2019-18874 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
pygments | CVE-2021-20270, CVE-2021-27291 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Python | CVE-2022-45061 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Python3 | CVE-2023-24329 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
rsync | CVE-2022-29154 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
slf4j-ext | CVE-2018-8088 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
sqlite3 | CVE-2022-35737 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
strongSwan | CVE-2021-45079, CVE-2021-41991, CVE-2021-41990 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
sudo | CVE-2022-43995, CVE-2023-22809 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
telnet | CVE-2022-39028 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Terracotta Quartz Scheduler | CVE-2019-13990 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
twisted | CVE-2022-24801, CVE-2022-21712 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
vim, vim-common, vim-data | CVE-2022-4292, CVE-2022-3520, CVE-2022-3591, CVE-2022-4141 |
See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
vmtools | CVE-2022-31676 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
woodstox | CVE-2022-40152, CVE-2022-40153 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
xen-libs | CVE-2022-42331, CVE-2022-42332, CVE-2022-42333, CVE-2022-42334 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
xterm, xterm-bin | CVE-2022-45063 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-32449 | Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks. | 7.2 | CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H |
CVE-2023-32478 |
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure. | 9.0 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H |
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-32449 | Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks. | 7.2 | CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H |
CVE-2023-32478 |
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure. | 9.0 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H |
Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
PowerStore 500T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-500t/drivers |
PowerStore 1000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-1000t/drivers |
PowerStore 1200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-1200t/drivers |
PowerStore 3000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-3000t/drivers |
PowerStore 3200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-3200t/drivers |
PowerStore 5000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-5000t/drivers |
PowerStore 5200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-5200t/drivers |
PowerStore 7000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-7000t/drivers |
PowerStore 9000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-9000t/drivers |
PowerStore 9200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-9200t/drivers |
Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
PowerStore 500T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-500t/drivers |
PowerStore 1000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-1000t/drivers |
PowerStore 1200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-1200t/drivers |
PowerStore 3000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-3000t/drivers |
PowerStore 3200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-3200t/drivers |
PowerStore 5000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-5000t/drivers |
PowerStore 5200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-5200t/drivers |
PowerStore 7000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-7000t/drivers |
PowerStore 9000T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-9000t/drivers |
PowerStore 9200T | PowerStoreT OS | Versions prior to 3.5.0.1-2083289 | Version 3.5.0.1-2083289 | https://www.dell.com/support/home/product-support/product/powerstore-9200t/drivers |
Revision | Date | Description |
---|---|---|
1.0 | 2023-06-20 | Initial Release |
2.0 | 2023-07-20 | Added additional Third-party components, Added additional Proprietary CVE, Updated Affected Product and Remediation Table |
3.0 | 2023-07-20 | Updated CVSS Base Score and CVSS Vector String for CVE-2023-32478 |
4.0 | 2024-01-08 | Updated for enhanced presentation with no change to content |
5.0 | 2024-04-29 | Updated for enhanced presentation with no change to content |
6.0 | 2024-06-12 | Updated for enhanced presentation with no change to content |
7.0 | 2024-06-13 | Updated for enhanced presentation with no change to content |