CVE-2021-36281: High severity Dell EMC PowerScale OneFS vulnerability
Published Aug 16, 2021
·Updated
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can potentially exploit this vulnerability to escalate privileges.
Affected Software
2 affected components
Dell EMC PowerScale OneFS>=9.0.0.0<=9.2.1
Dell EMC PowerScale OneFS=8.2.2
Remediation
Patch Available
Event History
Aug 16, 2021
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36281?
CVE-2021-36281 is classified as a medium severity vulnerability.
2
How do I mitigate CVE-2021-36281?
To mitigate CVE-2021-36281, update Dell EMC PowerScale OneFS to a version that is not vulnerable, specifically above 9.2.1 or any patched version.
3
Who is affected by CVE-2021-36281?
CVE-2021-36281 affects authenticated users of Dell EMC PowerScale OneFS versions 8.2.x to 9.2.x.
4
What type of vulnerability is CVE-2021-36281?
CVE-2021-36281 is an incorrect permission assignment vulnerability that allows privilege escalation.
5
Can CVE-2021-36281 be exploited remotely?
CVE-2021-36281 requires the attacker to be an authenticated user, hence it is not a remote exploit.