CVE-2021-21530
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from the restricted environment and gain access to sensitive information in the system, resulting in information disclosure and elevation of privilege.
Dell OpenManage Enterprise-Modular (OME-M) versiones anteriores a 1.30.00, contiene una vulnerabilidad de omisión de seguridad. Un usuario malicioso autenticado con pocos privilegios puede explotar la vulnerabilidad para escapar del entorno restringido y conseguir acceso a información confidencial en el sistema, resultando en una divulgación de información y elevación de privilegios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-04 CVE Reserved
- 2021-04-30 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/kbdoc/000185205 | 2021-05-10 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Openmanage Enterprise-modular Search vendor "Dell" for product "Openmanage Enterprise-modular" | < 1.30.00 Search vendor "Dell" for product "Openmanage Enterprise-modular" and version " < 1.30.00" | - |
Affected
|