CVE-2021-36338: High severity emc solutions enabler vulnerability
Published Jan 21, 2022
·Updated
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
Affected Software
13 affected components
Dell Solutions Enabler<9.1.0.18
Dell Solutions Enabler>=9.2.0.0<9.2.3.0
Dell Solutions Enabler Virtual Appliance<9.1.0.18
Dell Solutions Enabler Virtual Appliance>=9.2.0.0<9.2.3.0
Dell Unisphere 360<9.1.0.29
Dell Unisphere 360>=9.2.0.0<9.2.3.3
Dell Unisphere for PowerMax<9.1.0.31
Dell Unisphere for PowerMax>=9.2.0.0<9.2.3.4
Dell Unisphere For Powermax Virtual Appliance<9.1.0.31
Dell Unisphere For Powermax Virtual Appliance>=9.2.0.0<9.2.3.4
Dell Vasa<9.1.0.723
Dell Vasa>=9.2.0.0<9.2.3.0
Dell PowerMax OS=5978
Remediation
Patch Available
Event History
Jan 21, 2022
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-36338?
CVE-2021-36338 is a privilege escalation vulnerability in Unisphere for PowerMax versions prior to 9.2.2.2.
2
How does CVE-2021-36338 affect Dell Solutions Enabler?
Dell Solutions Enabler versions up to 9.1.0.18 are affected by CVE-2021-36338.
3
What versions of Dell Unisphere 360 are affected by CVE-2021-36338?
Dell Unisphere 360 versions up to 9.1.0.29 are affected by CVE-2021-36338.
4
How can I fix CVE-2021-36338?
To fix CVE-2021-36338, upgrade to Unisphere for PowerMax version 9.2.2.2 or higher.
5
What is the severity of CVE-2021-36338?
CVE-2021-36338 has a severity level of high.