Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-5367: DSA-2020-065: Dell EMC Unisphere for PowerMax, Dell EMC Unisphere for PowerMax Virtual Appliance, and Dell EMC PowerMax Embedded Management Update for Multiple Vulnerabilities

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim’s traffic to view or modify a victim’s data in transit.

CVE
#vulnerability#auth#dell

Vaikutus

High

Tiedot

Proprietary Code CVE(s)

Description

CVSSBase Score

CVSS Vector String

CVE-2020-5367

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim’s traffic to view or modify a victim’s data in transit.

Note: This CVE was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17. CVE-2021-21548 addresses incomplete fix for CVE-2020-5367.

7.4

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2020-5345

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics.

6.4

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

Proprietary Code CVE(s)

Description

CVSSBase Score

CVSS Vector String

CVE-2020-5367

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim’s traffic to view or modify a victim’s data in transit.

Note: This CVE was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17. CVE-2021-21548 addresses incomplete fix for CVE-2020-5367.

7.4

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2020-5345

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics.

6.4

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

Dell Technologies suosittelee, että kaikki asiakkaat ottavat huomioon sekä CVSS-peruspistemäärän että kaikki asiaankuuluvat väliaikaiset ja ympäristöön liittyvät pisteet, jotka voivat vaikuttaa tietyn tietoturvahaavoittuvuuden mahdolliseen vakavuuteen.

Tuotteet, joihin asia vaikuttaa ja tilanteen korjaaminen

Product

Affected Version(s)

Updated Version(s)

Link to Update

Unisphere for PowerMax

Versions prior to 9.1.0.17

9.1.0.27
EEM: 9.1.0.856

https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers

Unisphere for PowerMax Virtual Appliance

Versions prior to 9.1.0.17

9.1.0.27
EEM: 9.1.0.856

https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers

PowerMax OS

5978

5978

Request OPT 583679 for Foxtail SR and Hickory SR

Notes:

  • CVE-2020-5367 was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17.
  • DSA-2021-134 addresses the improper certificate validation vulnerability in the Dell EMC Unisphere for PowerMax version 9.1.0.27(CVE-2021-21548).
  • Dell EMC highly recommends all users upgrade Dell EMC Unisphere for PowerMax to version 9.1.0.27 at their earliest opportunity.

Product

Affected Version(s)

Updated Version(s)

Link to Update

Unisphere for PowerMax

Versions prior to 9.1.0.17

9.1.0.27
EEM: 9.1.0.856

https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers

Unisphere for PowerMax Virtual Appliance

Versions prior to 9.1.0.17

9.1.0.27
EEM: 9.1.0.856

https://www.dell.com/support/home/product-support/product/unisphere-powermax/drivers

PowerMax OS

5978

5978

Request OPT 583679 for Foxtail SR and Hickory SR

Notes:

  • CVE-2020-5367 was not fully addressed in the Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17.
  • DSA-2021-134 addresses the improper certificate validation vulnerability in the Dell EMC Unisphere for PowerMax version 9.1.0.27(CVE-2021-21548).
  • Dell EMC highly recommends all users upgrade Dell EMC Unisphere for PowerMax to version 9.1.0.27 at their earliest opportunity.

Keinoja ongelman kiertämiseen tai lieventämiseen

None.

Kiitokset

CVE-2020-5367: Dell would like to thank Thorsten Tüllmann from Karlsruhe Institute of Technology, Germany for reporting this issue.

Versiohistoria

Revision

Date

Description

1.0

2021-04-09

Initial Release

2.0

2021-10-04

Affected Component Type, CVE description, and Version Updated. Added note to Affected Products and Remediation section concerning CVE-2021-21548 addresses incomplete fix for CVE-2020-5367.

Asiaan liittyvät tiedot

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide

PowerMax 2000, PowerMax 8000, Product Security Information, Unisphere for PowerMax

04 lokak. 2021

Related news

CVE-2021-21548: DSA-2021-134: Dell EMC Unisphere for PowerMax, Dell EMC Unisphere for PowerMax Virtual Appliance, Dell EMC Solutions Enabler Virtual Appliance, and Dell EMC PowerMax Embedded Management Security Updat

Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.

CVE-2021-21548: DSA-2021-134: Dell EMC Unisphere for PowerMax, Dell EMC Unisphere for PowerMax Virtual Appliance, Dell EMC Solutions Enabler Virtual Appliance, and Dell EMC PowerMax Embedded Management Security Updat

Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907