DSA-2021-064: Dell EMC PowerScale OneFS Security Update for Multiple Vulnerabilities
Resumen: Dell EMC PowerScale OneFS remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Este artículo se aplica a:
Este artículo no se aplica a:
Este artículo no está vinculado a ningún producto específico.
En este artículo no se identifican todas las versiones de los productos.
Impacto
Critical
Detalles
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21527 | Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. | 6.0 | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
| CVE-2021-21550 | Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. | 6.0 | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21527 | Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. | 6.0 | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
| CVE-2021-21550 | Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. | 6.0 | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Productos afectados y corrección
| CVE(s) Addressed | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-21527 | 9.0.0.x | Upgrade your version of OneFS | PowerScale Download Area |
| 9.1.0.x | Download and install the April RUP | ||
| CVE-2021-21550 | 8.1.1, 8.2.1, and 9.0.0.x | Upgrade your version of OneFS | |
| 8.1.2, 8.2.2, and 9.1.0.x | Download and install the April RUP |
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
| CVE(s) Addressed | Affected Version(s) | Updated Version(s) | Link to Update |
| CVE-2021-21527 | 9.0.0.x | Upgrade your version of OneFS | PowerScale Download Area |
| 9.1.0.x | Download and install the April RUP | ||
| CVE-2021-21550 | 8.1.1, 8.2.1, and 9.0.0.x | Upgrade your version of OneFS | |
| 8.1.2, 8.2.2, and 9.1.0.x | Download and install the April RUP |
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Soluciones alternativas y mitigaciones
| CVE ID | Workaround(s) or Mitigation(s) |
| CVE-2021-21527 | None. Note: This only is a concern if you have enabled SmartLock Compliance Mode. |
| CVE-2021-21550 | None Note: This only is a concern if you have enabled SmartLock Compliance Mode. |
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2021-05-03 | Initial Release |
Información relacionada
Aviso legal
Productos afectados
Product Security InformationPropiedades del artículo
Número de artículo: 000185978
Tipo de artículo: Dell Security Advisory
Última modificación: 18 sept 2025
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.