Summary
Dell patched over 550 vulnerabilities in PowerProtect Cyber Recovery, including three critical flaws with CVSS scores of 10.0 that allow DNS manipulation and man-in-the-middle attacks. The updates address security flaws in the proprietary software, third-party libraries, and the underlying SUSE Linux operating system.
Take Action:
If you run Dell PowerProtect Cyber Recovery, update it to version 20.3.0.0 ASAP and also apply the matching SUSE Linux OS update. The fix isn't complete without both. After patching, check that any third-party components are on the fixed versions too, and keep the recovery vault reachable only from trusted internal networks, never the open internet.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)