CVE-2021-36298
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to authentication bypass and remote takeover of the InsightIQ. This allows an attacker to take complete control of InsightIQ to affect services provided by SSH; so Dell recommends customers to upgrade at the earliest opportunity.
Dell EMC InsightIQ versiones anteriores a 4.1.4, contienen algoritmos criptográficos arriesgados en el componente SSH. Un atacante remoto no autenticado podría potencialmente explotar esta vulnerabilidad conllevando a una omisión de la autenticación y a la toma remota del InsightIQ. Esto permite a un atacante tomar el control completo de InsightIQ para afectar a los servicios proporcionados por SSH; por lo que Dell recomienda a clientes que actualicen lo antes posible
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-08 CVE Reserved
- 2021-10-01 CVE Published
- 2024-06-16 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/kbdoc/000191604 | 2021-10-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Isilon Insightiq Firmware Search vendor "Dell" for product "Isilon Insightiq Firmware" | < 4.1.4 Search vendor "Dell" for product "Isilon Insightiq Firmware" and version " < 4.1.4" | - |
Affected
| in | Dell Search vendor "Dell" | Isilon Insightiq Search vendor "Dell" for product "Isilon Insightiq" | * | - |
Safe
|