First published: Mon Aug 02 2021(Updated: )
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application’s direct control.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Isilon OneFS | =8.1.2 | |
Dell EMC Isilon OneFS | =8.1.3 | |
Dell EMC Isilon OneFS | =9.0.0.0 | |
Dell EMC Isilon OneFS | =9.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21562 is classified as a high severity vulnerability due to its potential impact on system security.
To fix CVE-2021-21562, ensure that your Dell EMC PowerScale OneFS is updated to a patched version released by Dell.
CVE-2021-21562 affects users with privileges such as ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE and either ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT on specific versions of Dell EMC PowerScale OneFS.
CVE-2021-21562 affects Dell EMC PowerScale OneFS versions 8.1.2, 8.1.3, 9.0.0.0, and 9.1.0.0.
CVE-2021-21562 can allow an attacker with the necessary privileges to execute untrusted code, leading to potential unauthorized access or system compromise.