First published: Tue Nov 23 2021(Updated: )
Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged attacker, with the knowledge of the hard-coded credentials, may potentially exploit this vulnerability to gain unauthorized access to the system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Cloud Link | <7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36312 is classified as a high severity vulnerability due to the potential for unauthorized access by remote attackers.
To fix CVE-2021-36312, upgrade to Dell EMC CloudLink version 7.1.1 or later to eliminate the hard-coded password issue.
CVE-2021-36312 affects all versions of Dell EMC CloudLink up to and including version 7.1.0.
CVE-2021-36312 is a hard-coded password vulnerability that allows attackers with knowledge of the credentials to gain unauthorized system access.
Yes, CVE-2021-36312 can be exploited remotely by an attacker if they possess the hard-coded credentials.