« Volver al listado

CVE-2021-36339

Estado: ModificadaAlta (7.8)—

The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-36339",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Solutions Enabler vApp",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "9.2.2.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-01-21T21:15:08.563",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/000194640",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/000194640",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-250"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance."
    },
    {
      "lang": "es",
      "value": "Los dispositivos virtuales de Dell EMC versiones anteriores a 9.2.2.2, contienen cuentas de usuario no documentadas. Un usuario local malicioso puede explotar potencialmente esta vulnerabilidad para conseguir acceso privilegiado al dispositivo virtual"
    }
  ],
  "lastModified": "2026-06-17T03:58:42.093",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "515FA8C1-EBE4-4C95-A4F0-490A9253CBDC",
              "versionEndExcluding": "9.1.0.18"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B69897E-9004-4C03-BE06-55587AEE5988",
              "versionEndExcluding": "9.2.3.0",
              "versionStartIncluding": "9.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "019DA7BB-C234-430B-AC32-2E814E0891DF",
              "versionEndExcluding": "9.1.0.18"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "428D83E3-D8EC-4219-9B75-E9758EB00210",
              "versionEndExcluding": "9.2.3.0",
              "versionStartIncluding": "9.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EE42B7D-E49F-44F3-829E-BA72F1D42F7F",
              "versionEndExcluding": "9.1.0.29"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B164012E-60A3-48C6-BEB6-925A1F210BA1",
              "versionEndExcluding": "9.2.3.3",
              "versionStartIncluding": "9.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B34D944B-D1B6-4B10-9120-BBFC0CC244BA",
              "versionEndExcluding": "9.1.0.31"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1778817-3C6F-4448-A30E-2A63FC1113CA",
              "versionEndExcluding": "9.2.3.4",
              "versionStartIncluding": "9.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C672671E-0F6F-4501-8842-3BAB7A042DC5",
              "versionEndExcluding": "9.1.0.31"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72F83DE8-B2E7-4E27-8863-4AB2FCA3ABA9",
              "versionEndExcluding": "9.2.3.4",
              "versionStartIncluding": "9.2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D50A0BBF-0D40-433E-92AD-E30768920733",
              "versionEndExcluding": "9.1.0.723"
            },
            {
              "criteria": "cpe:2.3:a:dell:vasa:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "620ABE76-5646-455C-93C8-F6009C4E668D",
              "versionEndExcluding": "9.2.3.0",
              "versionStartIncluding": "9.2.0.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43696C46-48E8-43E4-9387-77CE1B2BD401"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}