CERT-In Vulnerability Note
CIVN-2021-0382
Multiple vulnerabilities in Dell EMC Unity
Original Issue Date:December 31, 2021
Severity Rating: HIGH
Systems Affected
- Dell Unity, Unity XT, and UnityVSA versions before 5.1.2.0.5.007
Overview
Multiple vulnerabilities have been reported in Dell Unity, Unity XT, and UnityVSA which could allow an attacker to access sensitive information, bypass security restrictions or perform a denial of service (DoS) condition on the targeted system.
Description
These vulnerabilities exist in Dell Unity, Unity XT, and UnityVSA due to operating system (OS) command injection vulnerability and vulnerabilities of bind, curl, dhcp, git, glib2, glibc, gnutls, libnettle, libX11, lz4, mgetty, mozilla-nspr, nghtstp2, open-iscsi, openldap2, openssl (Unisphere UI), openssl (NAS Server), polkit, postgresql10, python-tk, sudo components within the application.
Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, bypass security restrictions and perform a denial of service (DoS) condition on the targeted system.
Solution
Apply appropriate upgrade as mentioned in Dell Advisory
https://www.dell.com/support/kbdoc/en-in/000194836/dsa-2021-271-dell-emc-unity-dell-emc-unity-vsa-and-dell-emc-unity-xt-security-update-for-multiple-vulnerabilities
Vendor Information
Dell
https://www.dell.com/support/kbdoc/en-in/000194836/dsa-2021-271-dell-emc-unity-dell-emc-unity-vsa-and-dell-emc-unity-xt-security-update-for-multiple-vulnerabilities
References
Dell
https://www.dell.com/support/kbdoc/en-in/000194836/dsa-2021-271-dell-emc-unity-dell-emc-unity-vsa-and-dell-emc-unity-xt-security-update-for-multiple-vulnerabilities
CVE Name
CVE-2020-25696
CVE-2021-43589
CVE-2021-3712
CVE-2021-3560
CVE-2021-3520
CVE-2021-3326
CVE-2021-32028
CVE-2021-32027
CVE-2021-3177
CVE-2021-3156
CVE-2021-31535
CVE-2021-27219
CVE-2021-27218
CVE-2021-27212
CVE-2021-25217
CVE-2021-25215
CVE-2021-25214
CVE-2021-23987
CVE-2021-23984
CVE-2021-23982
CVE-2021-23981
CVE-2021-23840
CVE-2021-22898
CVE-2021-22876
CVE-2021-21300
CVE-2021-20305
CVE-2021-20232
CVE-2021-20231
CVE-2020-36230
CVE-2020-36229
CVE-2020-36228
CVE-2020-36227
CVE-2020-36226
CVE-2020-36225
CVE-2020-36224
CVE-2020-36223
CVE-2020-36222
CVE-2020-36221
CVE-2020-29573
CVE-2020-29573
CVE-2020-29562
CVE-2020-27618
CVE-2020-25695
CVE-2020-25694
CVE-2020-17438
CVE-2020-17437
CVE-2020-13988
CVE-2020-13987
CVE-2020-11080
CVE-2019-25013
CVE-2019-20916
CVE-2018-16745
CVE-2018-16744
CVE-2018-16743
CVE-2018-16742
CVE-2018-16741
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|