« Volver al listado

CVE-2021-43587

Estado: ModificadaMedia (6.7)—

Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-43587",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "PowerPath Management Appliance",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.2 P01",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-21T17:15:08.357",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000194083/dsa-2021-260",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000194083/dsa-2021-260",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-321"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges."
    },
    {
      "lang": "es",
      "value": "Dell PowerPath Management Appliance, versiones 3.2, 3.1, 3.0 P01, 3.0 y 2.6, usan una clave criptográfica embebida. Un usuario local malicioso con privilegios elevados podría explotar esta vulnerabilidad para conseguir acceso a los secretos y elevarse para conseguir privilegios superiores"
    }
  ],
  "lastModified": "2026-06-17T04:11:10.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:powerpath_management_appliance:2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52816B9C-22F2-441E-91F1-5259597B74A5"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerpath_management_appliance:3.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FEE04FA-1675-4981-ABBC-6B897F262D66"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerpath_management_appliance:3.0:patch_01:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "365876FA-46CC-4AD7-BD47-DC81526B543F"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerpath_management_appliance:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC22B1B0-E9A4-44F7-BAA3-7F3F592448FE"
            },
            {
              "criteria": "cpe:2.3:a:dell:powerpath_management_appliance:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D92273A9-3C81-4082-9550-DC1497AEDF39"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}