Dell (Dell iDRAC Service Module) Products January 2024 1st Security Update Advisory

Overview

 

Dell(https://www.dell.com) has released a security update that fixes vulnerabilities in its products. Affected product users are advised to update to the latest version.

 

Affected Products

 

IDRAC Service Module iSM 5.3.0.0 and earlier

 

Resolved Vulnerabilities

 

Vulnerability due to poor authorization management in Dell iDRAC Service Module (CVE-2024-22428, CVSS 7.0) [1]

 

Vulnerability Patches

 

Product-specific vulnerability patches were released in the 01/15/2024 update. For more information on vulnerability patches, please refer to the “Affected Products and Remediation” section of the product-specific reference site documentation.

IDRAC Service Module iSM 5.3.0.0 version

 

Referenced Sites

 

[1] DSA-2024-018: Security Update for Dell iDRAC Service Module for Weak Folder Permission Vulnerabilities

https://www.dell.com/support/kbdoc/en-us/000221129/dsa-2024-018-security-update-for-dell-idrac-service-module-for-weak-folder-permission-vulnerabilities