CVE-2021-21561: High severity dell emc isilon onefs vulnerability
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISIPRIVLOGINSSH and/or ISIPRIVLOGINCONSOLE privileges to gain access to sensitive information in the log files.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-21561?
CVE-2021-21561 is a vulnerability in Dell PowerScale OneFS version 8.1.2 that allows a malicious user to gain access to sensitive information in the log files.
How severe is CVE-2021-21561?
CVE-2021-21561 has a severity rating of 5.5, which is considered high.
Which versions of Dell PowerScale OneFS are affected by CVE-2021-21561?
Dell PowerScale OneFS version 8.1.2, 8.2.2, 9.0.0.0, 9.1.0.0, and 9.2.0.0 are all affected by CVE-2021-21561.
How can a malicious user exploit CVE-2021-21561?
A malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges can exploit CVE-2021-21561 to gain access to sensitive information in the log files.
Is there a fix for CVE-2021-21561?
Yes, Dell has released a fix for CVE-2021-21561. Please refer to Dell's support website for more information.