Lucene search

K
cveDellCVE-2021-21550
HistoryMay 06, 2021 - 1:15 p.m.

CVE-2021-21550

2021-05-0613:15:11
CWE-78
dell
web.nvd.nist.gov
24
4
cve-2021-21550
dell emc
powerscale
onefs
os command
privilege escalation
vulnerability
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

13.1%

Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability can allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.

Affected configurations

Nvd
Vulners
Node
dellemc_powerscale_onefsMatch8.1.1
OR
dellemc_powerscale_onefsMatch8.1.2
OR
dellemc_powerscale_onefsMatch8.2.1
OR
dellemc_powerscale_onefsMatch8.2.2
OR
dellemc_powerscale_onefsMatch9.0.0.0
OR
dellemc_powerscale_onefsMatch9.1.0.0
VendorProductVersionCPE
dellemc_powerscale_onefs8.1.1cpe:2.3:o:dell:emc_powerscale_onefs:8.1.1:*:*:*:*:*:*:*
dellemc_powerscale_onefs8.1.2cpe:2.3:o:dell:emc_powerscale_onefs:8.1.2:*:*:*:*:*:*:*
dellemc_powerscale_onefs8.2.1cpe:2.3:o:dell:emc_powerscale_onefs:8.2.1:*:*:*:*:*:*:*
dellemc_powerscale_onefs8.2.2cpe:2.3:o:dell:emc_powerscale_onefs:8.2.2:*:*:*:*:*:*:*
dellemc_powerscale_onefs9.0.0.0cpe:2.3:o:dell:emc_powerscale_onefs:9.0.0.0:*:*:*:*:*:*:*
dellemc_powerscale_onefs9.1.0.0cpe:2.3:o:dell:emc_powerscale_onefs:9.1.0.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "PowerScale OneFS",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "8.2.x, 9.1.x",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

13.1%

Related for CVE-2021-21550