QID 730119

Date Published: 2021-06-28

QID 730119: Dell Solutions Enabler Security Update for Multiple Third-Party Component Vulnerabilities

Solutions Enabler includes application programming interface (API) libraries that bridge software applications and the heterogeneous hardware and software infrastructure within a storage environment.

Affected Version:
Solutions Enabler and Solutions Enabler Virtual Appliance Versions prior to 9.1.0.15
Solutions Enabler and Solutions Enabler Virtual Appliance Versions prior to 9.2.1.1

QID Detection Logic:(Unauthenticated)
This QID sends a GET request to find if the target is running a vulnerable version of Solutions Enabler.

Successful exploitation of this vulnerability may allow a local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 7.6 severity.
  • Solution
    Vendor has released fix to this vulnerability.

    Customers are advised to refer to DSA-2021-063 for more information.

    Software Advisories
    Advisory ID Software Component Link
    DSA-2021-063 URL Logo www.dell.com/support/kbdoc/en-in/000184565/dsa-2021-063-dell-emc-unisphere-for-powermax-dell-emc-unisphere-for-powermax-virtual-appliance-dell-emc-solutions-enabler-virtual-appliance-and-dell-emc-powermax-embedded-management-security-update-for-multiple-third-party-component-vulnerabilities