Dell EMC Alert
2274Warning Date
Severity Level
Warning Number
Target Sector
9 August, 2023
● Critical
2023-5717
All
Description:
Dell EMC has released a security updates to address multiple vulnerabilities in the following products:
- Enterprise SONiC Distribution
- Dell SmartFabric Storage Software
- Dell SmartFabric OS10
Threats:
The attacker could exploit these vulnerabilities by doing the following:
- Improper Input Validation
- Privilege Escalation
- Sensitive Information Disclosure
- Denial of Service (DoS)
- Arbitrary Code Execution
Best practice and Recommendations:
The CERT team encourages users to review Dell EMC security advisory and apply the necessary updates:
- https://www.dell.com/support/kbdoc/en-us/000216584/dsa-2023-124-security-update-for-dell-smartfabric-os10-multiple-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000216586/dsa-2023-284-security-update-for-dell-emc-enterprise-sonic-os-command-injection-vulnerability-when-using-remote-user-authentication
- https://www.dell.com/support/kbdoc/en-us/000216587/dsa-2023-283-security-update-for-dell-smartfabric-storage-software-vulnerabilities