CVE-2021-36334: Medium severity qnap myqnapcloud link vulnerability
Published Nov 23, 2021
·Updated
Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to arbitrary code execution on end user machine
Affected Software
1 affected component
Dell Emc Cloud Link<7.1.1
Remediation
Event History
Nov 23, 2021
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36334?
CVE-2021-36334 has a high severity rating due to its potential for arbitrary code execution.
2
How does CVE-2021-36334 affect Dell EMC CloudLink?
CVE-2021-36334 affects Dell EMC CloudLink 7.1 and all prior versions, allowing high privileged remote attackers to exploit the vulnerability.
3
What are the potential consequences of exploiting CVE-2021-36334?
Exploiting CVE-2021-36334 could lead to arbitrary code execution on the end user's machine.
4
How do I fix CVE-2021-36334?
To fix CVE-2021-36334, update Dell EMC CloudLink to version 7.1.1 or later.
5
Is there a workaround for CVE-2021-36334 before applying the patch?
Currently, there are no known workarounds for CVE-2021-36334; applying the patch is recommended.