PT-2021-21233 · Dell Emc · Dell Emc Streaming Data Platform

Published

2021-11-30

·

Updated

2021-12-02

·

CVE-2021-36330

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Streaming Data Platform versions prior to 1.3
Description The issue allows a remote unauthenticated attacker to potentially reuse old session artifacts and impersonate a legitimate user due to insufficient session expiration.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider implementing additional session validation mechanisms to minimize the risk of exploitation. Restrict access to sensitive areas of the platform to minimize the risk of unauthorized access until the issue is resolved.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36330

Affected Products

Dell Emc Streaming Data Platform