Ga naar hoofdinhoud
  • Snel en eenvoudig bestellen
  • Bestellingen en de verzendstatus bekijken
  • Een lijst met producten maken en openen
  • Beheer uw Dell EMC locaties, producten en contactpersonen op productniveau met Company Administration.

Artikelnummer: 000185978


DSA-2021-064: Dell EMC PowerScale OneFS Security Update for Multiple Vulnerabilities

Samenvatting: Dell EMC PowerScale OneFS remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Article content


Impact

Critical

Gegevens

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21527 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVE-2021-21550 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21527 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVE-2021-21550 Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges. 6.0 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Dell Technologies raadt aan dat alle klanten rekening houden met zowel de basisscore van CVSS als alle relevante tijdelijke en omgevingsscores die gevolgen kunnen hebben voor de mogelijke ernst van de specifieke beveiligingsproblemen.

Getroffen producten en herstel

CVE(s) Addressed  Affected Version(s) Updated Version(s) Link to Update
CVE-2021-21527 9.0.0.x Upgrade your version of OneFS
PowerScale Download Area
9.1.0.x Download and install the April RUP
CVE-2021-21550 8.1.1, 8.2.1, and 9.0.0.x Upgrade your version of OneFS
8.1.2, 8.2.2, and 9.1.0.x Download and install the April RUP

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
CVE(s) Addressed  Affected Version(s) Updated Version(s) Link to Update
CVE-2021-21527 9.0.0.x Upgrade your version of OneFS
PowerScale Download Area
9.1.0.x Download and install the April RUP
CVE-2021-21550 8.1.1, 8.2.1, and 9.0.0.x Upgrade your version of OneFS
8.1.2, 8.2.2, and 9.1.0.x Download and install the April RUP

Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Tijdelijke oplossingen en beperkingen

CVE ID Workaround(s) or Mitigation(s)
CVE-2021-21527 None.
Note: This only is a concern if you have enabled SmartLock Compliance Mode.
CVE-2021-21550 None
Note: This only is a concern if you have enabled SmartLock Compliance Mode.

Revisiegeschiedenis

RevisionDateDescription
1.02021-05-03Initial Release

Verwante informatie

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide


Artikeleigenschappen


Getroffen product

Product Security Information

Datum laatst gepubliceerd

03 mei 2021

Versie

2

Artikeltype

Dell Security Advisory