CVE-2021-36287: OS Command Injection
Published Apr 8, 2022
·Updated
Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.
Affected Software
10 affected components
Dell EMC Unity Operating Environment<=8.1.21.266
Dell Vnx Vg10
Dell Vnx Vg50
Dell Vnx5200
Dell Vnx5400
Dell Vnx5600
Dell Vnx5800
Dell Vnx7600
Dell Vnx8000
Dell Vnxe1600
Event History
Apr 8, 2022
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Dell VNX2 vulnerability?
The vulnerability ID for this Dell VNX2 vulnerability is CVE-2021-36287.
2
What is the severity of CVE-2021-36287?
The severity of CVE-2021-36287 is critical with a score of 9.8.
3
What software versions are affected by CVE-2021-36287?
Dell VNX2 for file version 8.1.21.266 and earlier are affected by CVE-2021-36287.
4
How can an unauthenticated user exploit CVE-2021-36287?
An unauthenticated user can exploit CVE-2021-36287 to execute commands on the system.
5
How can I fix CVE-2021-36287?
To fix CVE-2021-36287, apply the security update provided by Dell and referenced in the Dell support knowledge base article.