DCS/CSP Manager and DCS/CSP Windows Agent update for CVE-2024-11477
search cancel

DCS/CSP Manager and DCS/CSP Windows Agent update for CVE-2024-11477

book

Article ID: 389537

calendar_today

Updated On:

Products

Data Center Security Monitoring Edition Data Center Security Server Data Center Security Server Advanced Critical System Protection Embedded Security Critical System Protection

Issue/Introduction

A new update for DCS/CSP Agents, Manager, Consoles is now available.

While DCS/CSP Agent/Managers function is not impacted by the CVE, we have provided updated installers to replace the version of the 3rd party component bundled in the Agent and Manager.

Environment

All Versions of CSP 7.x/8.x and DCS 6.x

DCS 6.10.x
 - Windows Agent DCS 6.10.9605 and lower
 - Communication Server 6.10.0.79 and lower
 - Management Server 6.10.0.180 and lower

DCS 6.x
 - Manager 6.9.3.370 and lower
 - Agent 6.9.3.2577 and lower

CSP - All Versions
 -- All CSP 7.x
 -- All CSP 8.x
 -- Manager 8.0.2.143 and lower
 -- Agent CSP 8.0.2.2063 and lower

 

Resolution

A 3rd Party component that DCS includes requires an update for CVE-2024-11477. This component is bundled with DCS / CSP Agent and Managers.

While DCS/CSP Agent/Managers function is not impacted by the CVE, we have provided updated installers to update the 3rd party component bundled in the Agent and Manager.

This can not be exploited if IPS is enabled and IPS Policy is applied with self protection.


Fixed Versions - Includes Component Version: 24.09
DCS 6.10.x
 - Windows Agent DCS 6.10.9606 and higher
 - Communication Server 6.10.0.80 and higher
 - Management Server 6.10.0.181 and higher

DCS 6.x
 - Manager 6.9.3.371 and higher
 - Agent 6.9.3.2578 and higher

CSP - All Versions
 -- Manager 8.0.2.144 and higher
 -- Agent CSP 8.0.2.2064 and higher

Additional Information

Please contact Technical Support for the updated installers and options available.