ID

VAR-202104-0668


CVE

CVE-2021-21526


TITLE

Dell Technologies Dell PowerScale OneFS Operating system command injection vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202104-1545

DESCRIPTION

Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary commands as root. Dell Technologies Dell PowerScale OneFS is an operating system of Dell Technologies in the United States. Offers the PowerScale OneFS operating system for scale-out NAS

Trust: 1.08

sources: NVD: CVE-2021-21526 // VULHUB: VHN-379930 // VULMON: CVE-2021-21526

AFFECTED PRODUCTS

vendor:dellmodel:powerscale onefsscope:lteversion:9.1.0

Trust: 1.0

vendor:dellmodel:powerscale onefsscope:gteversion:8.1.0

Trust: 1.0

sources: NVD: CVE-2021-21526

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-21526
value: MEDIUM

Trust: 1.0

security_alert@emc.com: CVE-2021-21526
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202104-1545
value: MEDIUM

Trust: 0.6

VULHUB: VHN-379930
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-21526
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-379930
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-21526
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

security_alert@emc.com: CVE-2021-21526
baseSeverity: MEDIUM
baseScore: 6.0
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.2
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-379930 // CNNVD: CNNVD-202104-1545 // NVD: CVE-2021-21526 // NVD: CVE-2021-21526

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.1

sources: VULHUB: VHN-379930 // NVD: CVE-2021-21526

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202104-1545

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-202104-1545

PATCH

title:Dell Technologies Dell PowerScale OneFS Fixes for operating system command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=147998

Trust: 0.6

sources: CNNVD: CNNVD-202104-1545

EXTERNAL IDS

db:NVDid:CVE-2021-21526

Trust: 1.8

db:CNNVDid:CNNVD-202104-1545

Trust: 0.7

db:VULHUBid:VHN-379930

Trust: 0.1

db:VULMONid:CVE-2021-21526

Trust: 0.1

sources: VULHUB: VHN-379930 // VULMON: CVE-2021-21526 // CNNVD: CNNVD-202104-1545 // NVD: CVE-2021-21526

REFERENCES

url:https://www.dell.com/support/kbdoc/000185202

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-21526

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-379930 // VULMON: CVE-2021-21526 // CNNVD: CNNVD-202104-1545 // NVD: CVE-2021-21526

SOURCES

db:VULHUBid:VHN-379930
db:VULMONid:CVE-2021-21526
db:CNNVDid:CNNVD-202104-1545
db:NVDid:CVE-2021-21526

LAST UPDATE DATE

2024-11-23T21:50:55.581000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-379930date:2021-04-27T00:00:00
db:VULMONid:CVE-2021-21526date:2021-04-27T00:00:00
db:CNNVDid:CNNVD-202104-1545date:2021-04-28T00:00:00
db:NVDid:CVE-2021-21526date:2024-11-21T05:48:31.500

SOURCES RELEASE DATE

db:VULHUBid:VHN-379930date:2021-04-20T00:00:00
db:VULMONid:CVE-2021-21526date:2021-04-20T00:00:00
db:CNNVDid:CNNVD-202104-1545date:2021-04-20T00:00:00
db:NVDid:CVE-2021-21526date:2021-04-20T17:15:11.537