CVE-2021-36295: OS Command Injection
Published Jan 25, 2022
·Updated
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.
Affected Software
9 affected components
Dell EMC Unity Operating Environment<=8.1.21.266
Dell Vnx Vg10
Dell Vnx Vg50
Dell Vnx5200
Dell Vnx5400
Dell Vnx5600
Dell Vnx5800
Dell Vnx7600
Dell Vnx8000
Event History
Jan 25, 2022
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36295?
CVE-2021-36295 is considered to have a high severity due to its potential for remote code execution.
2
How do I fix CVE-2021-36295?
To resolve CVE-2021-36295, it is recommended to update the Dell VNX2 OE for File to version 8.1.21.267 or later.
3
Who is affected by CVE-2021-36295?
CVE-2021-36295 affects users of Dell VNX2 OE for File versions 8.1.21.266 and earlier.
4
What type of vulnerability is CVE-2021-36295?
CVE-2021-36295 is classified as an authenticated remote code execution vulnerability.
5
Can CVE-2021-36295 be exploited remotely?
Yes, CVE-2021-36295 can be exploited remotely by a malicious user with the required privileges.