CVE-2021-21531Client-Side Enforcement of Server-Side Security in Dell Unisphere FOR Powermax

Severity
7.8HIGHNVD
CNA8.1
EPSS
0.1%
top 65.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateFeb 13

Description

Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5dell/unisphere_for_powermaxunspecified9.2.1.6
NVDdell/unisphere9.2.1.09.2.1.6+2
NVDdell/solutions_enabler9.2.09.2.1.6+1

🔴Vulnerability Details

3
OSV
fig2dev vulnerabilities2023-02-13
GHSA
GHSA-mmrw-4h5c-2pv5: Dell Unisphere for PowerMax versions prior to 92022-05-24
CVEList
CVE-2021-21531: Dell Unisphere for PowerMax versions prior to 92021-04-30
CVE-2021-21531 — Dell vulnerability | cvebase