DELL EMC Updates
2712Warning Date
Severity Level
Warning Number
Target Sector
15 December, 2021
● Critical
2021-4072
All
Description:
DELL EMC has released security updates to address the Apache log4j vulnerability in the following products:
- Connectrix B-Series SANnav
- Enterprise Hybrid Cloud
- Dell EMC Enterprise Storage Analytics for vRealize Operations
- Dell EMC VxRail
- Wyse Management Suite
- Dell EMC VxRail
- Dell Security Management Server
- Dell Data Protection | Encryption Server
- Dell Security Management Server Virtual
- Dell Data Protection | Encryption Server - Virtual
- Supporting Infrastructure
- Enterprise Hybrid Cloud
- Dell EMC Enterprise Storage Analytics for vRealize Operations
- Dell EMC Connectrix SANnav
- Dell Wyse Management Suite
Threats:
A remote attacker could exploit this vulnerability by executing arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review DELL EMC security advisory and apply the necessary updates:
- https://www.dell.com/support/kbdoc/en-us/000194372/dsn-2021-007-dell-response-to-apache-log4j-remote-code-execution-vulnerability
- https://www.dell.com/support/kbdoc/en-us/000194466/dsa-2021-265-dell-emc-vxrail-security-update-for-apache-log4j-remote-code-execution-vulnerability-cve-2021-44228
- https://www.dell.com/support/kbdoc/en-us/000194496/additional-information-for-dell-endpoint-security-in-regards-to-log4j-remote-code-execution-vulnerability-cve-2021-44228
- https://www.dell.com/support/kbdoc/en-us/000194490/dsa-2021-270-enterprise-hybrid-cloud-security-update-for-apache-log4j-remote-code-execution-vulnerability-cve-2021-44228
- https://www.dell.com/support/kbdoc/en-us/000194488/dsa-2021-278
- https://www.dell.com/support/kbdoc/en-us/000194461/dsa-2021-266-dell-emc-connectrix-b-series-sannav-security-update-for-apache-log4j-remote-code-execution-vulnerability-cve-2021-44228
- https://www.dell.com/support/kbdoc/en-us/000194459/dsa-2021-267-dell-wyse-management-suite-security-update-for-apache-log4j-remote-code-execution-vulnerability-cve-2021-44228