CVE-2021-36339

The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.
References
Link Resource
https://www.dell.com/support/kbdoc/000194640 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*

History

27 Oct 2022, 11:44

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-Other

28 Jan 2022, 15:11

Type Values Removed Values Added
References (MISC) https://www.dell.com/support/kbdoc/000194640 - (MISC) https://www.dell.com/support/kbdoc/000194640 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CPE cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*
First Time Dell solutions Enabler Virtual Appliance
Dell solutions Enabler
Dell
Dell unisphere For Powermax Virtual Appliance
Dell vasa
Dell powermax Os
Dell unisphere 360
Dell unisphere For Powermax
CWE CWE-269

21 Jan 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-21 21:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-36339

Mitre link : CVE-2021-36339

CVE.ORG link : CVE-2021-36339


JSON object : View

Products Affected

dell

  • solutions_enabler_virtual_appliance
  • powermax_os
  • vasa
  • unisphere_360
  • unisphere_for_powermax
  • solutions_enabler
  • unisphere_for_powermax_virtual_appliance
CWE
NVD-CWE-Other CWE-250

Execution with Unnecessary Privileges