CVE-2021-27006

Severity
4.4MEDIUM
EPSS
0.1%
top 80.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateDec 24

Description

StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings in SANtricity System Manager.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5storagegrid_(formerly_storagegrid_webscale)Versions 11.5 prior to 11.5.0.5
NVDnetapp/storagegrid11.5.011.5.0.5

🔴Vulnerability Details

2
GHSA
GHSA-r9wc-xprp-2665: StorageGRID (formerly StorageGRID Webscale) versions 112021-12-24
CVEList
CVE-2021-27006: StorageGRID (formerly StorageGRID Webscale) versions 112021-12-23