Dell family security update advisory
Overview
An update has been released to address vulnerabilities in the DELL family of products. Users of affected versions are advised to update to the latest version.
Affected Products
CVE-2024-22452
- Dell Display and Peripheral Manager for macOS prior to 1.3
CVE-2024-22433
- Dell Data Protection Search 19.2.0, 19.3.0, 19.4.0, 19.5.0, 19.5.1, 19.6.0, 19.6.1, 19.6.2, 19.6.3 versions
CVE-2024-22429
- PowerEdge T30 BIOS prior to 1.15.0
- Dell Edge Gateway 5000 BIOS prior to 1.28.0
- Dell Precision 5820 Tower BIOS prior to 2.36.0
- Edge Gateway 3000 series BIOS prior to 1.18.0
- Embedded Box PC 3000 BIOS prior to 1.24.0
- Embedded Box PC 5000 BIOS prior to 1.25.0
- Latitude 12 Rugged Extreme 7214 BIOS prior to 1.46.0
- Latitude 13 3380 BIOS prior to 1.27.0
- Latitude 3180 BIOS prior to 1.29.0
- Latitude 3189 BIOS prior to 1.29.0
- Latitude 3190 BIOS prior to 1.34.0
- Latitude 3190 2-in-1 BIOS prior to 1.34.0
- Latitude 3300 BIOS prior to 1.28.0
- Latitude 3390 2-in-1 BIOS prior to 1.31.0
- Latitude 5280 BIOS prior to 1.36.0
- Latitude 5288 BIOS prior to 1.36.0
- Latitude 5290 BIOS prior to 1.35.0
- Latitude 5290 2-in-1 BIOS prior to 1.34.0
- Latitude 5400 BIOS prior to 1.30.0
- Latitude 5414 Rugged BIOS prior to 1.46.0
- Latitude 5420 Rugged BIOS prior to 1.32.0
- Latitude 5424 Rugged BIOS prior to 1.32.0
- Latitude 5480 BIOS prior to 1.36.0
- Latitude 5488 BIOS prior to 1.36.0
- Latitude 5490 BIOS prior to 1.35.0
- Latitude 5580 BIOS prior to 1.36.0
- Latitude 5590 BIOS prior to 1.35.0
- Latitude 7212 Rugged Extreme Tablet BIOS prior to 1.50.0
- Latitude 7280 BIOS prior to 1.37.0
- Latitude 7285 2-in-1 BIOS prior to 1.26.0
- Latitude 7290 BIOS prior to 1.38.0
- Latitude 7380 BIOS prior to 1.37.0
- Latitude 7390 BIOS prior to 1.38.0
- Latitude 7390 2-IN-1 BIOS prior to 1.35.0
- Latitude 7414 Rugged BIOS prior to 1.46.0
- Latitude 7424 Rugged Extreme BIOS prior to 1.32.0
- Latitude 7480 BIOS prior to 1.37.0
- Latitude 7490 BIOS prior to 1.38.0
- OptiPlex 3050 BIOS prior to 1.30.0
- OptiPlex 3050 All-In-One BIOS prior to 1.32.0
- OptiPlex 5050 BIOS prior to 1.30.0
- OptiPlex 7450 All-In-One BIOS prior to 1.32.0
- Precision 3420 Tower BIOS prior to 2.30.0
- Precision 3520 BIOS prior to 1.36.0
- Precision 3620 Tower BIOS prior to 2.30.0
- Precision 5520 BIOS prior to 1.38.0
- Precision 5530 2-In-1 BIOS prior to 1.31.8
- Precision 7520 BIOS prior to 1.36.0
- Precision 7720 BIOS prior to 1.36.0
- Wyse 5070 BIOS prior to 1.31.0
- Wyse 7040 Thin Client BIOS prior to 1.25.0
CVE-2024-29170
- PowerScale OneFS versions: 8.2.x (inclusive) to 9.8.0.x (inclusive)
CVE-2024-25959, CVE-2024-25960
- PowerScale OneFS Versions: 8.2.2 (inclusive) to 9.3.0.0 (inclusive)
- PowerScale OneFS Versions: 9.4.0.0 (inclusive) to 9.4.0.16 (inclusive)
- PowerScale OneFS versions: 9.5.0.0 (inclusive) to 9.5.0.7 (inclusive)
- PowerScale OneFS versions: 9.6.1.0 (inclusive) to 9.7.0.1 (inclusive)
CVE-2024-22429
- PowerEdge T30 BIOS prior to 1.15.0
CVE-2024-25955, CVE-2024-25946
- Unisphere for PowerMax Virtual Appliance prior to 9.2.4.9
- Solutions Enabler Virtual Appliance prior to 9.2.4.6
- Dell PowerMax EEM Embedded Management 5978 version
CVE-2024-22453
- PowerEdge R730 prior to 2.19.0
- PowerEdge R730xd prior to 2.19.0
- PowerEdge R630 prior to 2.19.0
- PowerEdge C4130 prior to 2.19.0
- PowerEdge R930 prior to 2.14.0
- PowerEdge M630 prior to 2.19.0
- PowerEdge M630 (for PE VRTX) prior to 2.19.0
- PowerEdge FC630 prior to 2.19.0
- PowerEdge FC430 prior to 2.19.0
- PowerEdge M830 prior to 2.19.0
- PowerEdge M830 (for PE VRTX) prior to 2.19.0
- PowerEdge FC830 prior to 2.19.0
- PowerEdge T630 prior to 2.19.0
- PowerEdge R530 prior to 2.19.0
- PowerEdge R430 prior to 2.19.0
- PowerEdge T430 prior to 2.19.0
- PowerEdge R830 prior to 1.19.0
- PowerEdge C6320 prior to 2.19.0
- Dell Storage NX3230 prior to 2.19.0
- Dell Storage NX3330 prior to 2.19.0
- Dell XC6320 Hyper-converged Appliance prior to 2.19.0
- Dell XC430 Hyper-converged Appliance prior to 2.19.0
- Dell XC630 Hyper-converged Appliance prior to 2.19.0
- Dell XC730 Hyper-converged Appliance prior to 2.19.0
- Dell XC730XD Hyper-converged Appliance prior to 2.19.0
CVE-2024-25951
- iDRAC8 prior to 2.85.85.85
CVE-2024-0161
- PowerEdge T360 prior to 1.1.1
- PowerEdge R360 prior to 1.1.1
- PowerEdge R650 prior to 1.13.2
- PowerEdge R750 prior to 1.13.2
- PowerEdge R750XA prior to 1.13.2
- PowerEdge C6520 prior to 1.13.2
- PowerEdge MX750C prior to 1.13.2
- PowerEdge R550 prior to 1.13.2
- PowerEdge R450 prior to 1.13.2
- PowerEdge R650XS prior to 1.13.2
- PowerEdge R750XS prior to 1.13.2
- PowerEdge T550 prior to 1.13.2
- PowerEdge XR11 prior to 1.13.2
- PowerEdge XR12 prior to 1.13.2
- PowerEdge XR4510c prior to 1.14.1
- PowerEdge XR4520c prior to 1.14.1
- PowerEdge T150 prior to 1.9.1
- PowerEdge T350 prior to 1.9.1
- PowerEdge R250 prior to 1.9.1
- PowerEdge R350 prior to 1.9.1
- PowerEdge R740 prior to 2.21.2
- PowerEdge R740XD prior to 2.21.2
- PowerEdge R640 prior to 2.21.2
- PowerEdge R940 prior to 2.21.2
- PowerEdge R540 prior to 2.21.1
- PowerEdge R440 prior to 2.21.1
- PowerEdge T440 prior to 2.21.1
- PowerEdge XR2 prior to 2.21.1
- PowerEdge R740XD2 prior to 2.21.1
- PowerEdge R840 prior to 2.21.0
- PowerEdge R940XA prior to 2.21.0
- PowerEdge T640 prior to 2.21.0
- PowerEdge C6420 prior to 2.21.0
- PowerEdge FC640 prior to 2.21.0
- PowerEdge M640 prior to 2.21.1
- PowerEdge M640 (for PE VRTX) prior to 2.21.0
- PowerEdge MX740C prior to 2.21.0
- PowerEdge MX840C prior to 2.21.0
- PowerEdge C4140 prior to 2.21.1
- DSS 8440 prior to 2.21.0
- PowerEdge XE2420 prior to 2.21.1
- PowerEdge XE7420 prior to 2.21.0
- PowerEdge XE7440 prior to 2.21.0
- PowerEdge R730 prior to 2.19.0
- PowerEdge R730xd prior to 2.19.0
- PowerEdge R630 prior to 2.19.0
- PowerEdge C4130 prior to 2.19.0
- PowerEdge R930 prior to 2.14.0
- PowerEdge M630 prior to 2.19.0
- PowerEdge M630 (for PE VRTX) prior to 2.19.0
- PowerEdge FC630 prior to 2.19.0
- PowerEdge FC430 prior to 2.19.0
- PowerEdge M830 prior to 2.19.0
- PowerEdge M830 (for PE VRTX) prior to 2.19.0
- PowerEdge FC830 prior to 2.19.0
- PowerEdge T630 prior to 2.19.0
- PowerEdge R530 prior to 2.19.0
- PowerEdge R430 prior to 2.19.0
- PowerEdge T430 prior to 2.19.0
- PowerEdge R830 prior to 1.19.0
- PowerEdge C6320 prior to 2.19.0
- PowerEdge T130 prior to 2.20.0
- PowerEdge R230 prior to 2.20.0
- PowerEdge T330 prior to 2.20.0
- PowerEdge R330 prior to 2.20.0
- Dell EMC Storage NX3240 prior to 2.21.2
- Dell EMC Storage NX3340 prior to 2.21.2
- Dell Storage NX3230 prior to 2.19.0
- Dell Storage NX3330 prior to 2.19.0
- Dell Storage NX430 prior to 2.20.0
- Dell EMC XC Core XC450 prior to 1.13.2
- Dell EMC XC Core XC650 prior to 1.13.2
- Dell EMC XC Core XC750 prior to 1.13.2
- Dell EMC XC Core XC750xa prior to 1.13.2
- Dell EMC XC Core XC6520 prior to 1.13.2
- Dell EMC XC Core 6420 System prior to 2.21.0
- Dell EMC XC Core XC640 System prior to 2.21.2
- Dell EMC XC Core XC740xd System prior to 2.21.2
- Dell EMC XC Core XC740xd2 prior to 2.21.1
- Dell EMC XC Core XC940 System prior to 2.21.2
- Dell EMC XC Core XCXR2 prior to 2.21.1
- Dell XC6320 Hyper-converged Appliance prior to 2.19.0
- Dell XC430 Hyper-converged Appliance prior to 2.19.0
- Dell XC630 Hyper-converged Appliance prior to 2.19.0
- Dell XC730 Hyper-converged Appliance prior to 2.19.0
- Dell XC730XD Hyper-converged Appliance prior to 2.19.0
CVE-2023-48660, CVE-2023-48662, CVE-2023-48663, CVE-2023-48665, CVE-2023-48664, CVE-2023-48671
- Unisphere for PowerMax Virtual Appliance prior to 9.2.4.7
- Solutions Enabler Virtual Appliance prior to 9.2.4.5
- Dell PowerMax EEM version 5978
Resolved Vulnerabilities
Improper access control vulnerability in Dell Display and Peripheral Manager for macOS (CVE-2024-22452)
Vulnerability in Dell Data Protection Search when using LdapSettings.get_ldap_info to display in clear text (CVE-2024-22433)
Improper input validation vulnerability in Dell BIOS (CVE-2024-22429)
Sensitive information inclusion vulnerability in log files in Dell PowerScale OneFS (CVE-2024-25959)
Vulnerability in Dell PowerScale OneFS where sensitive information is sent in clear text (CVE-2024-25960)
Vulnerability in Dell PowerScale OneFS that uses hardcoded credentials (CVE-2024-29170)
Local privilege escalation vulnerability due to improper input validation in Dell BIOS (CVE-2024-22429)
Command injection vulnerability in Dell vAPP Manager that allows execution of injected commands (CVE-2024-25955, CVE-2024-25946)
Heap-based buffer overflow vulnerability in Dell PowerEdge server BIOS (CVE-2024-22453)
Command Injection Vulnerability in Dell Local RACADM (CVE-2024-25951)
Improper SMM communication buffer check vulnerability in Dell PowerEdge server BIOS and Dell Precision rack BIOS that could allow arbitrary writes (CVE-2024-0161)
Arbitrary file read vulnerability in Dell vApp Manger (CVE-2023-48660)
Arbitrary OS command execution vulnerability due to a command injection vulnerability in Dell vApp Manager (CVE-2023-48662, CVE-2023-48663, CVE-2023-48664)
Information disclosure vulnerability in Dell vApp Manager (CVE-2023-48671)
Vulnerability Patches
Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-22452
- Dell Display and Peripheral Manager for macOS in version 1.3 or at least
CVE-2024-22433
- Dell Data Protection Search 19.6.4 or later version
CVE-2024-22429
- PowerEdge T30 BIOS 1.15.0 or later
- Dell Edge Gateway 5000 BIOS 1.28.0 or later
- Dell Precision 5820 Tower BIOS 2.36.0 or later
- Edge Gateway 3000 series BIOS 1.18.0 or later
- Embedded Box PC 3000 BIOS 1.24.0 or later
- Embedded Box PC 5000 BIOS 1.25.0 or later
- Latitude 12 Rugged Extreme 7214 BIOS 1.46.0 or later
- Latitude 13 3380 BIOS 1.27.0 or later
- Latitude 3180 BIOS 1.29.0 or later
- Latitude 3189 BIOS 1.29.0 or later
- Latitude 3190 BIOS 1.34.0 or later
- Latitude 3190 2-in-1 BIOS 1.34.0 or later
- Latitude 3300 BIOS 1.28.0 or later
- Latitude 3390 2-in-1 BIOS 1.31.0 or later
- Latitude 5280 BIOS 1.36.0 or later
- Latitude 5288 BIOS 1.36.0 or later
- Latitude 5290 BIOS 1.35.0 or later
- Latitude 5290 2-in-1 BIOS 1.34.0 or later
- Latitude 5400 BIOS 1.30.0 or later
- Latitude 5414 Rugged BIOS 1.46.0 or later
- Latitude 5420 Rugged BIOS 1.32.0 or later
- Latitude 5424 Rugged BIOS 1.32.0 or later
- Latitude 5480 BIOS 1.36.0 or later
- Latitude 5488 BIOS 1.36.0 or later
- Latitude 5490 BIOS 1.35.0 or later
- Latitude 5580 BIOS 1.36.0 or later
- Latitude 5590 BIOS 1.35.0 or later
- Latitude 7212 Rugged Extreme Tablet BIOS 1.50.0 or later
- Latitude 7280 BIOS 1.37.0 or later
- Latitude 7285 2-in-1 BIOS 1.26.0 or later
- Latitude 7290 BIOS 1.38.0 or later
- Latitude 7380 BIOS 1.37.0 or later
- Latitude 7390 BIOS 1.38.0 or later
- Latitude 7390 2-IN-1 BIOS 1.35.0 or later
- Latitude 7414 Rugged BIOS 1.46.0 or later
- Latitude 7424 Rugged Extreme BIOS 1.32.0 or later
- Latitude 7480 BIOS 1.37.0 or later
- Latitude 7490 BIOS 1.38.0 or later
- OptiPlex 3050 BIOS 1.30.0 or later
- OptiPlex 3050 All-In-One BIOS 1.32.0 or later
- OptiPlex 5050 BIOS 1.30.0 or later
- OptiPlex 7450 All-In-One BIOS 1.32.0 or later
- Precision 3420 Tower BIOS 2.30.0 or later
- Precision 3520 BIOS 1.36.0 or later
- Precision 3620 Tower BIOS 2.30.0 or later
- Precision 5520 BIOS 1.38.0 or later
- Precision 5530 2-In-1 BIOS 1.31.8 or later
- Precision 7520 BIOS 1.36.0 or later
- Precision 7720 BIOS 1.36.0 or later
- Wyse 5070 BIOS 1.31.0 or later
- Wyse 7040 Thin Client BIOS 1.25.0 or later
CVE-2024-29170
- updated based on the “Workarounds and Mitigations” section of the reference site [5]
Cve-2024-25959, cve-2024-25960
- PowerScale OneFS 9.5.0.8 or later
- PowerScale OneFS 9.4.0.17 or later
- PowerScale OneFS 9.7.0.1 or later
CVE-2024-22429
- PowerEdge T30 BIOS version 1.15.0 or later
CVE-2024-25955
- Unisphere for PowerMax Virtual Appliance version 9.2.4.9 or later
- Solutions Enabler Virtual Appliance 9.2.4.6 version
- Dell PowerMax EEM Embedded Management 5978.714.714 Patch 10318 version
CVE-2024-22453
- PowerEdge R730 2.19.0 or later
- PowerEdge R730xd 2.19.0 or later
- PowerEdge R630 2.19.0 or later
- PowerEdge C4130 2.19.0 or later
- PowerEdge R930 2.14.0 or later
- PowerEdge M630 2.19.0 or later
- PowerEdge M630 (for PE VRTX) 2.19.0 or later
- PowerEdge FC630 2.19.0 or later
- PowerEdge FC430 2.19.0 or later
- PowerEdge M830 2.19.0 or later
- PowerEdge M830 (for PE VRTX) 2.19.0 or later
- PowerEdge FC830 2.19.0 or later
- PowerEdge T630 2.19.0 or later
- PowerEdge R530 2.19.0 or later
- PowerEdge R430 2.19.0 or later
- PowerEdge T430 2.19.0 or later
- PowerEdge R830 1.19.0 or later
- PowerEdge C6320 2.19.0 or later
- Dell Storage NX3230 2.19.0 or later
- Dell Storage NX3330 2.19.0 or later
- Dell XC6320 Hyper-converged Appliance 2.19.0 or later
- Dell XC430 Hyper-converged Appliance 2.19.0 or later
- Dell XC630 Hyper-converged Appliance 2.19.0 or later
- Dell XC730 Hyper-converged Appliance 2.19.0 or later
- Dell XC730XD Hyper-converged Appliance 2.19.0 or later
CVE-2024-25951
- iDRAC8 version 2.85.85.85 or later
CVE-2024-0161
- PowerEdge T360 1.1.1 or later
- PowerEdge R360 1.1.1 or later
- PowerEdge R650 1.13.2 or later
- PowerEdge R750 1.13.2 or later
- PowerEdge R750XA 1.13.2 or later
- PowerEdge C6520 1.13.2 or later
- PowerEdge MX750C 1.13.2 or later
- PowerEdge R550 1.13.2 or later
- PowerEdge R450 1.13.2 or later
- PowerEdge R650XS 1.13.2 or later
- PowerEdge R750XS 1.13.2 or later
- PowerEdge T550 1.13.2 or later
- PowerEdge XR11 1.13.2 or later
- PowerEdge XR12 1.13.2 or later
- PowerEdge XR4510c 1.14.1 or later
- PowerEdge XR4520c 1.14.1 or later
- PowerEdge T150 1.9.1 or later
- PowerEdge T350 1.9.1 or later
- PowerEdge R250 1.9.1 or later
- PowerEdge R350 1.9.1 or later
- PowerEdge R740 2.21.2 or later
- PowerEdge R740XD 2.21.2 or later
- PowerEdge R640 2.21.2 or later
- PowerEdge R940 2.21.2 or later
- PowerEdge R540 2.21.1 or later
- PowerEdge R440 2.21.1 or later
- PowerEdge T440 2.21.1 or later
- PowerEdge XR2 2.21.1 or later
- PowerEdge R740XD2 2.21.1 or later
- PowerEdge R840 2.21.0 or later
- PowerEdge R940XA 2.21.0 or later
- PowerEdge T640 2.21.0 or later
- PowerEdge C6420 2.21.0 or later
- PowerEdge FC640 2.21.0 or later
- PowerEdge M640 2.21.1 or later
- PowerEdge M640 (for PE VRTX) 2.21.0 or later
- PowerEdge MX740C 2.21.0 or later
- PowerEdge MX840C 2.21.0 or later
- PowerEdge C4140 2.21.1 or later
- DSS 8440 2.21.0 or later
- PowerEdge XE2420 2.21.1 or later
- PowerEdge XE7420 2.21.0 or later
- PowerEdge XE7440 2.21.0 or later
- PowerEdge R730 2.19.0 or later
- PowerEdge R730xd 2.19.0 or later
- PowerEdge R630 2.19.0 or later
- PowerEdge C4130 2.19.0 or later
- PowerEdge R930 2.14.0 or later
- PowerEdge M630 2.19.0 and later
- PowerEdge M630 (for PE VRTX) 2.19.0 and later
- PowerEdge FC630 2.19.0 or later version
- PowerEdge FC430 2.19.0 and at least 2.19.0
- PowerEdge M830 2.19.0 or later
- PowerEdge M830 (for PE VRTX) 2.19.0 or later
- PowerEdge FC830 2.19.0 or late
- PowerEdge T630 2.19.0 or later
- PowerEdge R530 2.19.0 or later
- PowerEdge R430 2.19.0 or later
- PowerEdge T430 2.19.0 or later
- PowerEdge R830 1.19.0 or later
- PowerEdge C6320 2.19.0 or later
- PowerEdge T130 2.20.0 or later
- PowerEdge R230 2.20.0 or later
- PowerEdge T330 2.20.0 or later
- PowerEdge R330 2.20.0 or later
- Dell EMC Storage NX3240 2.21.2 or later
- Dell EMC Storage NX3340 2.21.2 or later
- Dell Storage NX3230 2.19.0 or later
- Dell Storage NX3330 2.19.0 or later
- Dell Storage NX430 2.20.0 or later
- Dell EMC XC Core XC450 1.13.2 or later
- Dell EMC XC Core XC650 1.13.2 or later
- Dell EMC XC Core XC750 1.13.2 or later
- Dell EMC XC Core XC750xa 1.13.2 or later
- Dell EMC XC Core XC6520 1.13.2 or later
- Dell EMC XC Core 6420 System 2.21.0 or later
- Dell EMC XC Core XC640 System 2.21.2 or later
- Dell EMC XC Core XC740xd System 2.21.2 or later
- Dell EMC XC Core XC740xd2 2.21.1 or later
- Dell EMC XC Core XC940 System 2.21.2 or later
- Dell EMC XC Core XCXR2 2.21.1 or at least later
- Dell XC6320 Hyper-converged Appliance 2.19.0 or later
- Dell XC430 Hyper-converged Appliance 2.19.0 or later
- Dell XC630 Hyper-converged Appliance 2.19.0 or later
- Dell XC730 Hyper-converged Appliance 2.19.0 or later
- Dell XC730XD Hyper-converged Appliance 2.19.0 or later
CVE-2023-48660, CVE-2023-48662, CVE-2023-48663, CVE-2023-48665, CVE-2023-48664, CVE-2023-48671
- Unisphere for PowerMax Virtual Appliance 9.2.4.7 and later versions
- Solutions Enabler Virtual Appliance 9.2.4.5 and later versions
- Dell PowerMax EEM 5978.714.714 Patch 10120 version
Referenced Sites
[1] DSA-2024-200: Security Update for Dell PowerEdge T30 Mini Tower Server for an Improper Input Validation Vulnerability
[2] DSA-2024-108: Dell PowerMaxOS 5978, Dell PowerMax OS 10.0.1.5, Dell PowerMax OS 10.1.0.2, Dell Unisphere 360, Unisphere PowerMax, Unisphere PowerMax vApp, Dell Solutions Enabler vApp, and Dell PowerMax EEM Security Update for Multiple Vulnerabilities
[3] DSA-2024-105: Security Update for Dell PowerEdge Server BIOS for a Heap-based Buffer Overflow Vulnerability
[4] DSA-2024-089: Security Update for Dell iDRAC8 local RACADM Vulnerability
[5] DSA-2024-006: Security Update for Dell PowerEdge Server BIOS for an Improper SMM Communication Buffer Verification Vulnerability
[6] DSA-2023-429: Security Update for Dell 16G PowerEdge Server BIOS for a Debug Code Security Vulnerability
https://www.dell.com/support/kbdoc/ko-kr/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerability
[7] DSA-2023-443: Dell PowerMaxOS 5978, Dell Unisphere 360, Dell Unisphere for PowerMax, Dell Unisphere for PowerMax Virtual Appliance, Dell Solutions Enabler Virtual Appliance, and Dell PowerMax EEM Security Update for Multiple Vulnerabilities