CVE-2021-36332: Medium severity Dell Emc Cloud Link vulnerability
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and potentially malicious websites.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36332?
CVE-2021-36332 has a low severity rating due to the requirement for low privileged access and the exploitation method involving redirection.
How do I fix CVE-2021-36332?
To fix CVE-2021-36332, upgrade to Dell EMC CloudLink version 7.1.1 or later.
Who is affected by CVE-2021-36332?
CVE-2021-36332 affects all versions of Dell EMC CloudLink up to and including version 7.1.
What type of attack does CVE-2021-36332 enable?
CVE-2021-36332 enables HTML and Javascript injection attacks that can redirect users to malicious websites.
Is user interaction required for CVE-2021-36332 to be exploited?
Yes, exploitation of CVE-2021-36332 requires user interaction to navigate to the malicious website.