Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDell Emc Unity Operating Environment
APPDell≤ 8.1.21.266Dell Vnx5200
HWDellall versionsDell Vnx5400
HWDellall versionsDell Vnx5600
HWDellall versionsDell Vnx5800
HWDellall versionsDell Vnx7600
HWDellall versionsDell Vnx8000
HWDellall versionsDell Vnx Vg10
HWDellall versionsDell Vnx Vg50
HWDellall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
Related vulnerabilities
CVE-2018-1183CRITICAL9.8PL ✓same product
XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)
CVE-2021-36288HIGH8.6same product
Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unaut...
CVE-2021-36287HIGH7.3same product
Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerabil...
CVE-2021-36289HIGH7.8same product
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerabilit...
CVE-2021-36295HIGH7.2same product
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerab...