SB2022092810 - Multiple vulnerabilities in Dell EMC VxRail



SB2022092810 - Multiple vulnerabilities in Dell EMC VxRail

Published: September 28, 2022 Updated: September 18, 2023

Security Bulletin ID SB2022092810
Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2020-12966)

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to a Ciphertext side channel attack on ECC and DH operations in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local user with control over hypervisor can obtain sensitive data from the guest OS.


2) Input validation error (CVE-ID: CVE-2021-36346)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


3) Stack-based buffer overflow (CVE-ID: CVE-2021-36347)

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. An authenticated remote user with high privileges can exploit this vulnerability to control process execution and gain access to the iDRAC operating system.


4) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2021-36348)

The vulnerability allows a remote user to gain access to sensitive information or perform a denial of service attack.

The vulnerability exists due to an unspecified error in iDRAC9. A remote usee can exploit this vulnerability to gain access to sensitive information or perform a denial of service attack.


Remediation

Install update from vendor's website.