DELL EMC Update
2760Warning Date
Severity Level
Warning Number
Target Sector
28 March, 2021
● Critical
2021-2679
HealthCare
Description:
Dell EMC has released security update to address multiple vulnerabilities in the following product:
- Dell System Update (DSU)
- Dell Secure Remote Services Virtual Edition (SRS)
- kernel-default-base
- SUDO
- Openssl-1
Libopenssl1 - Python-2
Python-base-2
Python-xml-2
Libpython2
- Dell Unisphere for PowerMax, Dell Unisphere for PowerMax Virtual Appliance, Dell Solutions Enabler Virtual Appliance, and Dell PowerMax Embedded Management
- Oracle
- Spring Framework
- OpenSSL
- Internet Explorer 11
- Microsoft .NET
- Windows 10
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Unauthorized disclosure of information
- Memory Corruption
Best practice and Recommendations:
The CERT team encourages users to review Dell EMC security advisory and apply the necessary updates:
- https://www.dell.com/support/kbdoc/en-us/000184565/dsa-2021-063-dell-emc-unisphere-for-powermax-dell-emc-unisphere-for-powermax-virtual-appliance-dell-emc-solutions-enabler-virtual-appliance-and-dell-emc-powermax-embedded-management-security-update-for-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000184608/dsa-2021-059-dell-emc-system-update-dsu-security-update-for-denial-of-service-vulnerability
- https://www.dell.com/support/kbdoc/en-us/000184620/dsa-2021-053-dell-emc-srs-virtual-edition-security-update-for-multiple-third-party-component-vulnerabilities