Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDell Emc Unity Operating Environment
APPDell≤ 8.1.21.266Dell Vnx5200
HWDellwszystkie wersjeDell Vnx5400
HWDellwszystkie wersjeDell Vnx5600
HWDellwszystkie wersjeDell Vnx5800
HWDellwszystkie wersjeDell Vnx7600
HWDellwszystkie wersjeDell Vnx8000
HWDellwszystkie wersjeDell Vnx Vg10
HWDellwszystkie wersjeDell Vnx Vg50
HWDellwszystkie wersje
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
RCECommand Injection
Powiązane podatności
CVE-2021-36294CRITICAL9.8PL ✓ten sam produkt
Auth Bypass w Dell VNX2 OE for File — fałszowanie cookie
CVE-2018-1183CRITICAL9.8PL ✓ten sam produkt
XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)
CVE-2021-36288HIGH8.6ten sam produkt
Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unaut...
CVE-2021-36287HIGH7.3ten sam produkt
Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerabil...
CVE-2021-36289HIGH7.8ten sam produkt
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerabilit...