PT-2021-14642 · Dell Emc · Dell Emc Powerscale Onefs

Published

2021-08-16

·

Updated

2021-08-25

·

CVE-2021-21599

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC PowerScale OneFS versions 8.2.x through 9.2.1.x
Description The issue is an OS command injection vulnerability that may allow a user with ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE privileges to escalate privileges and escape compliance guarantees. This vulnerability specifically impacts Smartlock WORM compliance mode clusters.
Recommendations For Dell EMC PowerScale OneFS versions 8.2.x through 9.2.1.x, update or upgrade at the earliest opportunity to resolve the issue. As a temporary workaround, consider restricting access to the ISI PRIV LOGIN SSH and ISI PRIV LOGIN CONSOLE privileges to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21599

Affected Products

Dell Emc Powerscale Onefs