First published: Mon Aug 02 2021(Updated: )
Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerScale OneFS | <=9.1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21565 is a vulnerability in Dell PowerScale OneFS versions 9.1.0.3 and earlier that can be exploited to cause a denial of service.
CVE-2021-21565 affects Dell PowerScale OneFS versions 9.1.0.3 and earlier by causing a denial of service by triggering a loop in SmartConnect.
CVE-2021-21565 has a severity score of 5.3 (medium).
CVE-2021-21565 can be exploited by triggering a loop in SmartConnect, which uses CPU and potentially prevents other SmartConnect DNS responses.
Yes, Dell has released a fix for CVE-2021-21565. Please refer to the Dell support page for more information.