PT-2021-14565 · Dell · Powerscale Onefs
Published
2021-03-08
·
Updated
2021-03-12
·
CVE-2021-21506
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PowerScale OneFS versions 8.1.2, 8.2.2, and 9.1.0
Description
The issue is related to improper input sanitization in the API handler. An unauthenticated user with
ISI PRIV SYS SUPPORT and ISI PRIV LOGIN PAPI privileges could potentially exploit this, leading to potential privileges escalation.Recommendations
For PowerScale OneFS version 8.1.2, update to a version that fixes the improper input sanitization issue in the API handler.
For PowerScale OneFS version 8.2.2, update to a version that fixes the improper input sanitization issue in the API handler.
For PowerScale OneFS version 9.1.0, update to a version that fixes the improper input sanitization issue in the API handler.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerscale Onefs