CVE-2021-21595: Command Injection
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunity.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21595?
CVE-2021-21595 is classified as a critical vulnerability.
How do I fix CVE-2021-21595?
To fix CVE-2021-21595, upgrade Dell EMC PowerScale OneFS to version 9.2.0 or later.
Who is affected by CVE-2021-21595?
CVE-2021-21595 affects users of Dell EMC PowerScale OneFS versions 8.2.x to 9.1.1.x in Smartlock WORM compliance mode.
What type of vulnerability is CVE-2021-21595?
CVE-2021-21595 is an improper neutralization of special elements used in an OS command vulnerability.
What can happen if CVE-2021-21595 is exploited?
If CVE-2021-21595 is exploited, it could allow the compadmin user to elevate privileges.