CVE-2021-21526: OS Command Injection
Published Apr 20, 2021
·Updated
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary commands as root.
Affected Software
2 affected components
Dell PowerScale OneFS>=8.1.0<=9.1.0
Dell PowerScale OneFS>=8.1.0<=9.1.0
Event History
Apr 20, 2021
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this Dell PowerScale OneFS vulnerability?
The vulnerability ID of this Dell PowerScale OneFS vulnerability is CVE-2021-21526.
2
What is the severity of the CVE-2021-21526 vulnerability?
The severity of the CVE-2021-21526 vulnerability is high with a CVSS score of 6.7.
3
What is the affected software of the CVE-2021-21526 vulnerability?
The affected software of the CVE-2021-21526 vulnerability is Dell PowerScale OneFS versions 8.1.0 to 9.1.0.
4
How does the CVE-2021-21526 vulnerability work?
The CVE-2021-21526 vulnerability allows compadmin to execute arbitrary commands as root in SmartLock compliance mode.
5
Is there a fix for the CVE-2021-21526 vulnerability?
Yes, Dell has released a fix for the CVE-2021-21526 vulnerability. Please refer to the Dell support website for more information.