PT-2021-7427 · Dell · Dell Powerscale Onefs
Published
2021-02-08
·
Updated
2022-07-12
·
CVE-2021-21502
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell PowerScale OneFS versions 8.1.0 through 9.1.0
Description
The issue is related to a flaw in the authentication procedure when using an account with an expired term. This could allow a remote attacker to gain unauthorized access to protected information. A user on the network with the ISI PRIV AUTH SSH RBAC privilege and an expired account may exploit this, giving them access to the same privileges they had before account expiration, potentially including high-privileged accounts.
Recommendations
For Dell PowerScale OneFS versions 8.1.0 through 9.1.0, upgrade to a newer version at the earliest opportunity to resolve the issue. As a temporary workaround, consider restricting the ISI PRIV AUTH SSH RBAC privilege to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Powerscale Onefs