PT-2024-9245 · Dell · Dell Data Lakehouse+4
Published
2024-03-06
·
Updated
2026-01-22
·
CVE-2024-37143
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00
Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train)
Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0
Dell InsightIQ versions prior to 5.1.1
Dell Data Lakehouse versions prior to 1.2.0.0
Description:
The issue is related to an Improper Link Resolution Before File Access vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to execute arbitrary code on the system.
Recommendations:
For Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, update to a version that is IC 46.381.00 or later, or IC 46.376.00 or later.
For Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train), update to RCM 3.8.1.0 or later.
For Dell PowerFlex rack versions prior to RCM 3.7.6.0 (for RCM 3.7.x train), update to RCM 3.7.6.0 or later.
For Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, update to version 4.6.1.0 or later.
For Dell InsightIQ versions prior to 5.1.1, update to version 5.1.1 or later.
For Dell Data Lakehouse versions prior to 1.2.0.0, update to version 1.2.0.0 or later.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Data Lakehouse
Dell Insightiq
Dell Powerflex Appliance
Dell Powerflex Custom Node
Dell Powerflex Rack