PT-2021-21229 · Dell Emc · Dell Emc Streaming Data Platform
Published
2021-11-30
·
Updated
2021-12-01
·
CVE-2021-36327
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell EMC Streaming Data Platform versions prior to 1.3
Description
The issue allows a remote unauthenticated attacker to potentially exploit it and perform port scanning of internal networks. It also enables the attacker to make HTTP requests to an arbitrary domain of their choice.
Recommendations
For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to internal networks and limiting the ability to make HTTP requests to arbitrary domains until the update is applied.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Streaming Data Platform