DSA-2021-064: Dell EMC PowerScale OneFS Security Update for Multiple Vulnerabilities

Resumo: Dell EMC PowerScale OneFS remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Este artigo aplica-se a Este artigo não se aplica a Este artigo não está vinculado a nenhum produto específico. Nem todas as versões do produto estão identificadas neste artigo.

Impacto

Critical

Dados

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21527 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVE-2021-21550 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21527 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVE-2021-21550 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
A Dell Technologies recomenda que todos os clientes levem em consideração a pontuação base CVSS e as pontuações temporais e ambientais pertinentes que possam afetar a gravidade potencial associada a uma vulnerabilidade de segurança específica.

Produtos afetados e soluções

CVE(s) Addressed  Affected Version(s) Updated Version(s) Link to Update
CVE-2021-21527 9.0.0.x Upgrade your version of OneFS
PowerScale Download Area
9.1.0.x Download and install the April RUP
CVE-2021-21550 8.1.1, 8.2.1, and 9.0.0.x Upgrade your version of OneFS
8.1.2, 8.2.2, and 9.1.0.x Download and install the April RUP

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
CVE(s) Addressed  Affected Version(s) Updated Version(s) Link to Update
CVE-2021-21527 9.0.0.x Upgrade your version of OneFS
PowerScale Download Area
9.1.0.x Download and install the April RUP
CVE-2021-21550 8.1.1, 8.2.1, and 9.0.0.x Upgrade your version of OneFS
8.1.2, 8.2.2, and 9.1.0.x Download and install the April RUP

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Soluções temporárias e atenuações

CVE ID Workaround(s) or Mitigation(s)
CVE-2021-21527 None.
Note: This only is a concern if you have enabled SmartLock Compliance Mode.
CVE-2021-21550 None
Note: This only is a concern if you have enabled SmartLock Compliance Mode.

Histórico de revisão

RevisionDateDescription
1.02021-05-03Initial Release

Informações relacionadas

Produtos afetados

Product Security Information
Propriedades do artigo
Número do artigo: 000185978
Tipo de artigo: Dell Security Advisory
Último modificado: 18 set. 2025
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.