DSA-2021-172: Dell Isilon InsightIQ Security Update for a Proprietary Component Vulnerability

Summary: Dell Isilon InsightIQ remediation is available for Proprietary Component that could be exploited by malicious users to compromise the affected systems.

Acest articol se aplică pentru Acest articol nu se aplică pentru Acest articol nu este legat de un produs specific. Acest articol nu acoperă toate versiunile de produs existente.

Impact

High

Details

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-36298 Dell Isilon InsightIQ, versions prior to 4.1.4, contain Risky Cryptographic Algorithm in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to authentication bypass and remote takeover of the InsightIQ. This allows an attacker to take complete control of InsightIQ to affect services provided by SSH; Dell recommends customers to upgrade at the earliest opportunity. 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-36298 Dell Isilon InsightIQ, versions prior to 4.1.4, contain Risky Cryptographic Algorithm in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to authentication bypass and remote takeover of the InsightIQ. This allows an attacker to take complete control of InsightIQ to affect services provided by SSH; Dell recommends customers to upgrade at the earliest opportunity. 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Produse afectate și măsuri de remediere

CVE(s) Addressed Product Affected Version(s) Updated Version(s) Link to Update
CVE-2021-36298 Isilon InsightIQ 4.1.3.88 4.1.4.57
 
https://www.dell.com/support/home/en-in/product-support/product/isilon-insightiq/drivers
Select Version 4.1.4 and Package based on requirement.
  1. Isilon InsightIQ 4.1.4 Installation File for Linux Computers
  2. Isilon InsightIQ 4.1.4 Installation File for Other Supported VMware Products
  3. Isilon InsightIQ 4.1.4 Installation File for VMware ESX, VMware ESXi, or VMware Workstation
  4. Isilon InsightIQ 4.1.4 Patch file for Linux computers
CVE(s) Addressed Product Affected Version(s) Updated Version(s) Link to Update
CVE-2021-36298 Isilon InsightIQ 4.1.3.88 4.1.4.57
 
https://www.dell.com/support/home/en-in/product-support/product/isilon-insightiq/drivers
Select Version 4.1.4 and Package based on requirement.
  1. Isilon InsightIQ 4.1.4 Installation File for Linux Computers
  2. Isilon InsightIQ 4.1.4 Installation File for Other Supported VMware Products
  3. Isilon InsightIQ 4.1.4 Installation File for VMware ESX, VMware ESXi, or VMware Workstation
  4. Isilon InsightIQ 4.1.4 Patch file for Linux computers

Soluții alternative și strategii de atenuare

None

Revision History

RevisionDateDescription
0.12021-09-17Initial Release.

Related Information

Produse afectate

Product Security Information
Proprietăți articol
Article Number: 000191604
Article Type: Dell Security Advisory
Ultima modificare: 18 Sep 2025
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.