DSA-2022-210: Dell CloudLink Security Update for Multiple Security Vulnerabilities
摘要: Dell CloudLink remediation is available for SSM Agent console access security issue that may be exploited by malicious users to compromise the affected system.
影響
Critical
詳細資料
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2022-34380 |
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability as it allows attacker to take control of the system. |
9.1 |
| Third-party Component |
CVEs |
More information |
| Ubuntu 16.04 ESM: GNU C Library vulnerabilities (USN-5310-2) |
See NVD (http://nvd.nist.gov/ |
|
| Ubuntu 16.04 ESM: klibc vulnerabilities (USN-5379-1) |
||
| Ubuntu 16.04 ESM: Rsyslog vulnerability (USN-5404-2) |
||
| Ubuntu 16.04 ESM: Linux kernel vulnerabilities (USN-5413-1) |
||
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2022-34380 |
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability as it allows attacker to take control of the system. |
9.1 |
| Third-party Component |
CVEs |
More information |
| Ubuntu 16.04 ESM: GNU C Library vulnerabilities (USN-5310-2) |
See NVD (http://nvd.nist.gov/ |
|
| Ubuntu 16.04 ESM: klibc vulnerabilities (USN-5379-1) |
||
| Ubuntu 16.04 ESM: Rsyslog vulnerability (USN-5404-2) |
||
| Ubuntu 16.04 ESM: Linux kernel vulnerabilities (USN-5413-1) |
||
受影響的產品與補救措施
| Product | Affected Versions | Updated Version | Link to Update |
| Dell Cloudlink | Versions before 7.1.4 | 7.1.4 | CloudLink Downloads |
| Product | Affected Versions | Updated Version | Link to Update |
| Dell Cloudlink | Versions before 7.1.4 | 7.1.4 | CloudLink Downloads |
因應措施與緩解措施
Customers can disable SSM Agent following instructions in the Dell article 200819: CloudLink : Disable AWS console access to CloudLink OS.
修訂歷史記錄
|
Revision |
Date |
Description |
|
1.0 |
2022-08-01 |
Initial Release |