First published: Tue Jan 25 2022(Updated: )
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Operating Environment | <=8.1.21.266 | |
Dell Vnx Vg10 | ||
Dell Vnx Vg50 | ||
Dell Vnx5200 | ||
Dell Vnx5400 | ||
Dell Vnx5600 | ||
Dell Vnx5800 | ||
Dell Vnx7600 | ||
Dell Vnx8000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36294 is an authentication bypass vulnerability in Dell VNX2 OE for File versions 8.1.21.266 and earlier.
A remote unauthenticated attacker can exploit CVE-2021-36294 by forging a cookie to log in as any user.
Dell VNX2 OE for File versions 8.1.21.266 and earlier are affected by CVE-2021-36294.
CVE-2021-36294 has a severity rating of 9.8 (critical).
To fix CVE-2021-36294, apply the Dell VNX2 control station security update provided by Dell.