QID 730344

Date Published: 2022-02-07

QID 730344: Dell Solutions Enabler Out-of-bounds Write Vulnerability

Solutions Enabler includes application programming interface (API) libraries that bridge software applications and the heterogeneous hardware and software infrastructure within a storage environment.

Affected Version:
Solutions Enabler and Solutions Enabler Virtual Appliance Versions prior to 9.1.0.16
Solutions Enabler and Solutions Enabler Virtual Appliance Versions prior to 9.2.1.2

QID Detection Logic:(Unauthenticated)
This QID sends a GET request to find if the target is running a vulnerable version of Solutions Enabler.

An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Vendor has released fix to this vulnerability.

    Customers are advised to refer to DSA-2021-134 for more information.

    CVEs related to QID 730344

    Software Advisories
    Advisory ID Software Component Link
    DSA-2021-134 URL Logo www.dell.com/support/kbdoc/en-in/000189606/dsa-2021-134-dell-emc-unisphere-for-powermax-dell-emc-unisphere-for-powermax-virtual-appliance-dell-emc-solutions-enabler-virtual-appliance-and-dell-emc-powermax-embedded-management-security-update-for-multiple-third-party-component-vulnerabilities