CVE-2021-21567

Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege.
References
Link Resource
https://www.dell.com/support/kbdoc/000189495 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerscale_onefs:9.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerscale_onefs:9.1.0.0:*:*:*:*:*:*:*

History

26 Apr 2022, 15:32

Type Values Removed Values Added
CWE CWE-732 CWE-269

17 Aug 2021, 20:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CWE CWE-732
CPE cpe:2.3:a:dell:powerscale_onefs:9.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerscale_onefs:9.1.0.0:*:*:*:*:*:*:*
References (CONFIRM) https://www.dell.com/support/kbdoc/000189495 - (CONFIRM) https://www.dell.com/support/kbdoc/000189495 - Patch, Vendor Advisory

10 Aug 2021, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-10 19:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-21567

Mitre link : CVE-2021-21567

CVE.ORG link : CVE-2021-21567


JSON object : View

Products Affected

dell

  • powerscale_onefs
CWE
CWE-269

Improper Privilege Management

CWE-732

Incorrect Permission Assignment for Critical Resource