CVE-2021-36294
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
Affected (1)
Products: Dell: Emc Unity Operating Environment
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 8.1.21.266 |
| Running on/with | Platform Versions |
|---|---|
Dell Vnx5200 | All versions |
Dell Vnx5400 | All versions |
Dell Vnx5600 | All versions |
Dell Vnx5800 | All versions |
Dell Vnx7600 | All versions |
Dell Vnx8000 | All versions |
Dell Vnx Vg10 | All versions |
Dell Vnx Vg50 | All versions |
Related CWEs
CWE-330
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CWE-331
Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
References (2)
Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.