CVE-2021-36279: High severity dell emc isilon onefs vulnerability
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISIPRIVLOGINSSH or ISIPRIVLOGINCONSOLE to access privileged information about the cluster.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36279?
CVE-2021-36279 is rated as a high severity vulnerability due to the incorrect permission assignment allowing unauthorized access to sensitive cluster information.
How do I fix CVE-2021-36279?
To fix CVE-2021-36279, upgrade to Dell EMC PowerScale OneFS version 9.2.2 or later or apply vendor-provided patches.
Which versions of Dell EMC PowerScale OneFS are affected by CVE-2021-36279?
CVE-2021-36279 affects Dell EMC PowerScale OneFS versions 8.2.x through 9.2.x, including 8.2.2.
What kind of access does CVE-2021-36279 allow?
CVE-2021-36279 allows users with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster.
Is there any workaround for CVE-2021-36279?
Currently, there are no known workarounds for CVE-2021-36279, and patching is the recommended solution.