CVE-2021-21568: Medium severity dell emc isilon onefs vulnerability
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An authenticated user with ISIPRIVLOGINPAPI could make un-audited and un-trackable configuration changes to settings that their roles have privileges to change.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21568?
CVE-2021-21568 is classified as a high severity vulnerability due to the potential for untracked configuration changes.
How do I fix CVE-2021-21568?
To remediate CVE-2021-21568, ensure that you update Dell EMC PowerScale OneFS to a patched version that addresses the logging oversight.
Who is affected by CVE-2021-21568?
Authenticated users with ISI_PRIV_LOGIN_PAPI privileges on Dell EMC PowerScale OneFS versions 8.2.x to 9.2.x are affected by CVE-2021-21568.
What kind of changes can be made due to CVE-2021-21568?
CVE-2021-21568 allows unauthorized audit and tracking of configuration changes made by users with specific privileges.
Is there a workaround for CVE-2021-21568?
Currently, there is no specific workaround for CVE-2021-21568 other than upgrading to a secure version.