Dell EMC Alert
3023Warning Date
Severity Level
Warning Number
Target Sector
6 March, 2022
● Critical
2022-4479
All
Dell EMC has released security updates to address several vulnerabilities in the following products:
- Dell EMC SRM
- Versions before 4.7.0.1
- Dell EMC SRM Vapp
- Versions before 4.7.0.1
- Dell EMC SMR
- Versions before 4.7.0.1
- Dell EMC SMR Vapp
- Versions before 4.7.0.1
- Dell EMC Integrated System for Microsoft Azure Stack Hub
- 2112 and earlier
An attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack
- Disclosure of information
- Privilege escalation
- Remote code execution
The CERT team encourages users to review Dell EMC security advisory and apply the necessary updates:
- https://www.dell.com/support/kbdoc/en-us/000196956/dsa-2022-049-dell-emc-srm-and-dell-emc-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000196968/dsa-2022-060-dell-emc-integrated-system-for-microsoft-azure-stack-hub-security-update-for-multiple-third-party-component-vulnerabilities