CVE-2021-36294: Critical severity dell emc unity xt operating environment vulnerability
Published Jan 25, 2022
·Updated
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
Affected Software
9 affected components
Dell EMC Unity Operating Environment<=8.1.21.266
Dell Vnx Vg10
Dell Vnx Vg50
Dell Vnx5200
Dell Vnx5400
Dell Vnx5600
Dell Vnx5800
Dell Vnx7600
Dell Vnx8000
Event History
Jan 25, 2022
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-36294?
CVE-2021-36294 is an authentication bypass vulnerability in Dell VNX2 OE for File versions 8.1.21.266 and earlier.
2
How can an attacker exploit CVE-2021-36294?
A remote unauthenticated attacker can exploit CVE-2021-36294 by forging a cookie to log in as any user.
3
Which software versions are affected by CVE-2021-36294?
Dell VNX2 OE for File versions 8.1.21.266 and earlier are affected by CVE-2021-36294.
4
What is the severity of CVE-2021-36294?
CVE-2021-36294 has a severity rating of 9.8 (critical).
5
How can I fix CVE-2021-36294?
To fix CVE-2021-36294, apply the Dell VNX2 control station security update provided by Dell.