Vulnerability Description
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges may exploit this vulnerability to access sensitive information. If any third-party consumes those logs, the same sensitive information is available to those systems as well.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Powerscale Onefs | >= 8.2.0, <= 8.2.2 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000190408PatchVendor Advisory
- https://www.dell.com/support/kbdoc/000190408PatchVendor Advisory
FAQ
What is CVE-2021-36278?
CVE-2021-36278 is a vulnerability with a CVSS score of 8.1 (HIGH). Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSO...
How severe is CVE-2021-36278?
CVE-2021-36278 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36278?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Emc Powerscale Onefs.