DELL Alert
11113Warning Date
Severity Level
Warning Number
Target Sector
25 May, 2022
● Critical
2022-4877
All
Dell EMC has released security update to address several vulnerabilities in the following products:
- Dell Client
- PowerProtect DD Appliances model: DD6900, DD9400, DD9900, and DD3300
- 7.0 to 7.7
- 7.8
- PowerProtect DD Appliances model: DD6400
- 7.7
- 7.8
- Dell EMC Integrated Data Protection Appliance
- 2.7.2, 2.7.1, 2.7.0, 2.6.x, 2.5, 2.4.x, 2.3.x, and 2.2
An attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Sensitive information disclosure
- Excuate Arbirtary Code - remotely
The CERT team encourages users to review Dell EMC security advisory and apply the necessary update:
- https://www.dell.com/support/kbdoc/en-us/000200050/dsa-2022-146-dell-emc-integrated-data-protection-appliance-security-update-for-idrac-component-vulnerability
- https://www.dell.com/support/kbdoc/en-us/000199904/dsa-2022-140-dell-technologies-powerprotect-data-domain-security-update-for-idrac9-vnc-console-authentication-vulnerability
- https://www.dell.com/support/kbdoc/en-us/000196063/dsa-2022-040