First published: Mon Aug 16 2021(Updated: )
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can potentially allow an authenticated user with ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to gain access up to 24 bytes of data within the /ifs kernel stack under certain conditions.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Isilon OneFS | >=9.0.0.0<9.2.0 | |
Dell EMC Isilon OneFS | =8.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36282 is rated as having a medium severity due to its potential to expose sensitive data.
To fix CVE-2021-36282, upgrade your Dell EMC PowerScale OneFS to version 9.2.0 or later.
CVE-2021-36282 affects users of Dell EMC PowerScale OneFS versions 8.2.x to 9.1.0.x.
CVE-2021-36282 is a use of uninitialized resource vulnerability.
No, CVE-2021-36282 requires authenticated users with specific privileges to be exploited.