CVE-2021-21599: Command Injection
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISIPRIVLOGINSSH or ISIPRIVLOGINCONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunity.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21599?
CVE-2021-21599 is considered a critical vulnerability due to its potential for privilege escalation in compliance mode clusters.
How do I fix CVE-2021-21599?
To remediate CVE-2021-21599, update Dell EMC PowerScale OneFS to version 9.2.2 or later, or apply any available security patches.
What versions of Dell EMC PowerScale OneFS are affected by CVE-2021-21599?
CVE-2021-21599 affects Dell EMC PowerScale OneFS versions 8.2.x through 9.2.1.x.
Who is at risk from CVE-2021-21599?
Users with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges on Smartlock WORM compliance mode clusters are at risk from CVE-2021-21599.
Is there a workaround for CVE-2021-21599?
There are no documented workarounds for CVE-2021-21599, and it is recommended to apply the fix by upgrading to a secure version.