CVE-2021-36278: High severity dell emc isilon onefs vulnerability
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISIPRIVLOGINSSH, ISIPRIVLOGINCONSOLE, or ISIPRIVSYSSUPPORT privileges may exploit this vulnerability to access sensitive information. If any third-party consumes those logs, the same sensitive information is available to those systems as well.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36278?
CVE-2021-36278 has a medium severity rating due to potential sensitive information exposure.
How do I fix CVE-2021-36278?
To fix CVE-2021-36278, update the affected Dell EMC PowerScale OneFS to a version that patches this vulnerability.
Who can exploit CVE-2021-36278?
CVE-2021-36278 can be exploited by local malicious users with specific privileges such as ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE.
What is the impact of CVE-2021-36278?
The impact of CVE-2021-36278 is the unauthorized access to sensitive information contained in the log files.
Which versions of OneFS are affected by CVE-2021-36278?
CVE-2021-36278 affects Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1.