CVE-2021-21599

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/08/2021
Last modified:
25/08/2021

Description

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.0.0.0 (including) 9.2.1 (including)
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools