Vulnerability Description
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Solutions Enabler | < 9.1.0.18 |
| Dell | Solutions Enabler Virtual Appliance | < 9.1.0.18 |
| Dell | Unisphere 360 | < 9.1.0.29 |
| Dell | Unisphere For Powermax | < 9.1.0.31 |
| Dell | Unisphere For Powermax Virtual Appliance | < 9.1.0.31 |
| Dell | Vasa | < 9.1.0.723 |
| Dell | Powermax Os | 5978 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000194640PatchVendor Advisory
- https://www.dell.com/support/kbdoc/000194640PatchVendor Advisory
FAQ
What is CVE-2021-36338?
CVE-2021-36338 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and...
How severe is CVE-2021-36338?
CVE-2021-36338 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36338?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Solutions Enabler, Dell Solutions Enabler Virtual Appliance, Dell Unisphere 360, Dell Unisphere For Powermax, Dell Unisphere For Powermax Virtual Appliance.