跳至主要內容
  • 簡單快速地下訂單
  • 檢視訂單及追蹤商品運送狀態
  • 建立並存取您的產品清單

DSA-2021-311: Dell EMC XC Series and Core Appliance Security Update for Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105)

摘要: Dell EMC XC Series and Core Appliance remediation is available for the Apache Log4j Remote Code Execution Vulnerability that may be exploited by malicious users to compromise the affected system. Dell recommends implementing this remediation as soon as possible in light of the critical severity of the vulnerability. ...

本文章適用於 本文章不適用於 本文無關於任何特定產品。 本文未識別所有產品版本。

影響

Critical

詳細資料

Third-party Component CVEs More information
Apache Log4j CVE-2021-44228, CVE-2021-45046, CVE-2021-45105  Apache Log4j Remote Code Execution
Third-party Component CVEs More information
Apache Log4j CVE-2021-44228, CVE-2021-45046, CVE-2021-45105  Apache Log4j Remote Code Execution
Dell Technologies 建議所有客戶不僅要參考 CVSS 基本分數,也要將可能會影響與特定安全漏洞相關之潛在嚴重性的所有相關暫時和環境分數納入考量。

受影響的產品與補救措施

The table below shows the affected products and components impacted for the Dell EMC XC Series and Core Appliances.
 
Product  Affected Versions  Updated Versions  Link to Update 
Nutanix AOS 6.0 STS (Short Term Support) Branch only
 
STS versions before 6.0.2.4  6.0.2.4 Patched in AOS 6.0.2.4, available from the Nutanix Support Portal (https://my.nutanix.com [Nutanix login required])
Nutanix Objects
 
All versions  No patch; mitigation only  Mitigation is available.
See Nutanix article: https://portal.nutanix.com/kb/12482

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.


Information with solid fillNOTE: To determine if additional features and software purchased directly from Nutanix are affected, see Nutanix Advisory: Nutanix Security Advisory #0023.
 
Dell EMC PowerTools (PTAgent) and iDRAC Service Module (iSM) software components that are included with XC Series and Core Appliances are unaffected.
The table below shows the affected products and components impacted for the Dell EMC XC Series and Core Appliances.
 
Product  Affected Versions  Updated Versions  Link to Update 
Nutanix AOS 6.0 STS (Short Term Support) Branch only
 
STS versions before 6.0.2.4  6.0.2.4 Patched in AOS 6.0.2.4, available from the Nutanix Support Portal (https://my.nutanix.com [Nutanix login required])
Nutanix Objects
 
All versions  No patch; mitigation only  Mitigation is available.
See Nutanix article: https://portal.nutanix.com/kb/12482

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.


Information with solid fillNOTE: To determine if additional features and software purchased directly from Nutanix are affected, see Nutanix Advisory: Nutanix Security Advisory #0023.
 
Dell EMC PowerTools (PTAgent) and iDRAC Service Module (iSM) software components that are included with XC Series and Core Appliances are unaffected.

因應措施與緩解措施

Additional workarounds and mitigations for the Nutanix Software available at Nutanix Security Advisory #0023.

修訂歷史記錄

RevisionDateDescription
1.02021-12-29Initial Release

相關資訊

受影響的產品

XC Core Systems, XC Series Appliances

產品

Dell EMC XC Core XCXR2, Dell EMC XC Core XC450, Dell EMC XC Core XC650, Dell EMC XC Core XC6520, Dell EMC XC Core XC740xd2, Dell EMC XC Core XC750, Dell EMC XC Core XC750xa, Dell EMC XC Series XC640 Appliance, Dell EMC XC Core XC640 System , Dell EMC XC Series XC6420 Appliance, Dell EMC XC Core 6420 System, Dell EMC XC Series XC740xd Appliance, Dell EMC XC Core XC740xd System, Dell EMC XC Series XC940 Appliance, Dell EMC XC Core XC940 System, Product Security Information, Dell EMC XC Core XC7525 ...
文章屬性
文章編號: 000194822
文章類型: Dell Security Advisory
上次修改時間: 29 12月 2021
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。