Executive brief
Dell VxRail hyper-converged infrastructure appliances contain a security flaw where the api-gateway container runs with excessive (root) privileges. An attacker with local access to the system could exploit this configuration to break out of the isolated container environment and gain unauthorized access to the underlying host operating system. This could lead to a compromise of the entire appliance, potentially impacting data confidentiality and system availability.
Technical details
A privilege management vulnerability (CWE-269) exists in the api-gateway component of Dell VxRail. The container is configured to run with root privileges, which facilitates a container escape to the host operating system. An attacker with low-privileged local access can exploit this misconfiguration to perform unintended actions on the host system. The attack complexity is considered high, but successful exploitation results in a scope change (S:C), impacting the host environment beyond the container boundary. The issue is remediated in Dell VxRail version 7.0.520.
Affected products
- Dell VxRail Appliance 7.0.x versions prior to 7.0.520
Timeline
- 2024-06-16: disclosed
- 2024-06-20: advisory: Initial release of DSA-2024-247
- 2024-06-16: patched: Remediated in version 7.0.520