CVE-2021-36338

Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
References
Link Resource
https://www.dell.com/support/kbdoc/000194640 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*

History

09 Dec 2022, 16:26

Type Values Removed Values Added
CWE CWE-669 CWE-565

31 Aug 2022, 20:15

Type Values Removed Values Added
Summary Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.

28 Jan 2022, 15:17

Type Values Removed Values Added
CPE cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*
References (MISC) https://www.dell.com/support/kbdoc/000194640 - (MISC) https://www.dell.com/support/kbdoc/000194640 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.2
v3 : 8.0
First Time Dell solutions Enabler Virtual Appliance
Dell solutions Enabler
Dell
Dell unisphere For Powermax Virtual Appliance
Dell vasa
Dell powermax Os
Dell unisphere 360
Dell unisphere For Powermax
CWE CWE-669

21 Jan 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-21 21:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-36338

Mitre link : CVE-2021-36338

CVE.ORG link : CVE-2021-36338


JSON object : View

Products Affected

dell

  • solutions_enabler
  • powermax_os
  • vasa
  • solutions_enabler_virtual_appliance
  • unisphere_for_powermax_virtual_appliance
  • unisphere_360
  • unisphere_for_powermax
CWE
CWE-565

Reliance on Cookies without Validation and Integrity Checking

CWE-602

Client-Side Enforcement of Server-Side Security