Dell EMC Alert
2508Warning Date
Severity Level
Warning Number
Target Sector
26 April, 2022
● High
2022-4714
All
Dell EMC has released security updates to address several vulnerabilities in the following products:
- Dell EMC NetWorker vProxy
- 4.3.0-17 and earlier
- PowerPath Management Appliance
- 3.0
- 3.0 P01
- 3.1
- 3.2
- 3.2 P01
- 3.2 SP1
- PowerPath Linux
- 7.4
- PowerPath Windows
- 7.0
- 6.5
- 6.4
- Dell EMC Elastic Cloud Storage
- All supported ECS versions
Attacker could exploit these vulnerabilities by doing the following:
- Escalation of privilege
- Execute arbitrary code
The CERT team encourages users to review Dell EMC security advisory and apply the necessary updates:
- https://www.dell.com/support/kbdoc/en-us/000198849/dsa-2022-109-dell-emc-networker-vproxy-security-update-for-multiple-third-party-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000198826/dsa-2022-108-powerpath-and-powerpath-management-appliance-security-update-for-openssl-vulnerability
- https://www.dell.com/support/kbdoc/en-us/000198814/dsa-2022-034-dell-emc-ecs-security-update-for-multiple-idrac-vulnerabilities