PT-2021-21229 · Dell Emc · Dell Emc Streaming Data Platform

Published

2021-11-30

·

Updated

2021-12-01

·

CVE-2021-36327

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC Streaming Data Platform versions prior to 1.3
Description The issue allows a remote unauthenticated attacker to potentially exploit it and perform port scanning of internal networks. It also enables the attacker to make HTTP requests to an arbitrary domain of their choice.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to internal networks and limiting the ability to make HTTP requests to arbitrary domains until the update is applied.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36327

Affected Products

Dell Emc Streaming Data Platform