PT-2021-21213 · Dell Emc · Dell Emc Networker

Cesar Neira

·

Published

2021-11-23

·

Updated

2022-04-25

·

CVE-2021-36311

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Networker versions prior to 19.5
Description The issue allows a local malicious user with networker user privileges to upload a malicious file to unauthorized locations and execute it. This is due to an improper authorization vulnerability.
Recommendations For versions prior to 19.5, update to version 19.5 or later to resolve the issue. As a temporary workaround, consider restricting networker user privileges to minimize the risk of exploitation. Restrict access to file upload functionality to authorized users only until the issue is resolved.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36311

Affected Products

Dell Emc Networker