// For flags

CVE-2021-36294

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.

Dell VNX2 OE for File versiones 8.1.21.266 y anteriores, contienen una vulnerabilidad de omisión de autenticación. Un atacante remoto no autenticado puede explotar esta vulnerabilidad al falsificar una cookie para iniciar sesión como cualquier usuario

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-08 CVE Reserved
  • 2022-01-25 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-330: Use of Insufficiently Random Values
  • CWE-331: Insufficient Entropy
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx Vg10
Search vendor "Dell" for product "Vnx Vg10"
--
Safe
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx Vg50
Search vendor "Dell" for product "Vnx Vg50"
--
Safe
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx5200
Search vendor "Dell" for product "Vnx5200"
--
Safe
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx5400
Search vendor "Dell" for product "Vnx5400"
--
Safe
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx5600
Search vendor "Dell" for product "Vnx5600"
--
Safe
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx5800
Search vendor "Dell" for product "Vnx5800"
--
Safe
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx7600
Search vendor "Dell" for product "Vnx7600"
--
Safe
Dell
Search vendor "Dell"
Emc Unity Operating Environment
Search vendor "Dell" for product "Emc Unity Operating Environment"
<= 8.1.21.266
Search vendor "Dell" for product "Emc Unity Operating Environment" and version " <= 8.1.21.266"
-
Affected
in Dell
Search vendor "Dell"
Vnx8000
Search vendor "Dell" for product "Vnx8000"
--
Safe