SB2023010516 - Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub



SB2023010516 - Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub

Published: January 5, 2023 Updated: September 18, 2023

Security Bulletin ID SB2023010516
Severity
Medium
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 56% Low 44%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2022-24423)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause resource exhaustion in the webserver, resulting in a denial of service condition.


2) Infinite loop (CVE-ID: CVE-2022-0778)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the BN_mod_sqrt() function when processing an ASN.1 certificate that contains elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. A remote attacker can supply a specially crafted certificate to the TLS server or client, consume all available system resources and cause denial of service conditions.


3) NULL pointer dereference (CVE-ID: CVE-2019-14584)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a NULL pointer dereference error. A local user can run a specially crafted program to escalate privileges on the system.


4) Uncontrolled Recursion (CVE-ID: CVE-2021-28210)

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to an unlimited recursion in DxeCore. A local user can execute arbitrary code on the target system.


5) Heap-based buffer overflow (CVE-ID: CVE-2021-28211)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within the LzmaUefiDecompressGetInfo() function. A local user can run a specially crafted program to trigger a heap-based buffer overflow and execute arbitrary code with elevated privileges.


6) Out-of-bounds read (CVE-ID: CVE-2021-3712)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition when processing ASN.1 strings related to a confusion with NULL termination of strings in array. A remote attacker can pass specially crafted data to the application to trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.


7) Input validation error (CVE-ID: CVE-2021-36346)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


8) Stack-based buffer overflow (CVE-ID: CVE-2021-36347)

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. An authenticated remote user with high privileges can exploit this vulnerability to control process execution and gain access to the iDRAC operating system.


9) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2021-36348)

The vulnerability allows a remote user to gain access to sensitive information or perform a denial of service attack.

The vulnerability exists due to an unspecified error in iDRAC9. A remote usee can exploit this vulnerability to gain access to sensitive information or perform a denial of service attack.


Remediation

Install update from vendor's website.