CVE-2021-36282: Low severity dell emc isilon onefs vulnerability
Published Aug 16, 2021
·Updated
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can potentially allow an authenticated user with ISIPRIVLOGINCONSOLE or ISIPRIVLOGINSSH privileges to gain access up to 24 bytes of data within the /ifs kernel stack under certain conditions.
Affected Software
2 affected components
Dell EMC PowerScale OneFS>=9.0.0.0<9.2.0
Dell EMC PowerScale OneFS=8.2.2
Remediation
Patch Available
Event History
Aug 16, 2021
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36282?
CVE-2021-36282 is rated as having a medium severity due to its potential to expose sensitive data.
2
How do I fix CVE-2021-36282?
To fix CVE-2021-36282, upgrade your Dell EMC PowerScale OneFS to version 9.2.0 or later.
3
Who is affected by CVE-2021-36282?
CVE-2021-36282 affects users of Dell EMC PowerScale OneFS versions 8.2.x to 9.1.0.x.
4
What type of vulnerability is CVE-2021-36282?
CVE-2021-36282 is a use of uninitialized resource vulnerability.
5
Can an unauthorized user exploit CVE-2021-36282?
No, CVE-2021-36282 requires authenticated users with specific privileges to be exploited.