Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21595

Опубликовано: 16 авг. 2021
Источник: nvd
CVSS3: 6
CVSS3: 6.7
CVSS2: 4.6
EPSS Низкий

Описание

Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunity.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:*
Версия от 9.0.0.0 (включая) до 9.2.0 (исключая)
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00137
Низкий

6 Medium

CVSS3

6.7 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-77
CWE-77

Связанные уязвимости

github
больше 3 лет назад

Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunity.

EPSS

Процентиль: 34%
0.00137
Низкий

6 Medium

CVSS3

6.7 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-77
CWE-77