« Volver al listado

CVE-2021-21531

Estado: ModificadaAlta (7.8)—

Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21531",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Unisphere for PowerMax",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "9.2.1.6",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-04-30T21:15:08.673",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/000184565",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/000184565",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-602"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-669"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions."
    },
    {
      "lang": "es",
      "value": "Dell Unisphere para PowerMax versiones anteriores a 9.2.1.6, contienen una vulnerabilidad de Omisión de Autorización. Un usuario malicioso local autenticado con role de monitor puede explotar esta vulnerabilidad para llevar a cabo acciones no autorizadas."
    }
  ],
  "lastModified": "2026-06-17T03:35:43.650",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC3DAEF1-0C50-4683-ADD8-DFF2A82CA9B3",
              "versionEndExcluding": "9.1.0.15"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1A1B910-6302-4097-8AEB-CD3DA665A5B2",
              "versionEndExcluding": "9.2.1.6",
              "versionStartIncluding": "9.2.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A6E2D9A-1E3A-4671-8D11-7A0C51C3CFBB",
              "versionEndExcluding": "9.1.0.15"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F854B320-C194-4FA9-B972-EFFE909E9005",
              "versionEndExcluding": "9.2.1.1",
              "versionStartIncluding": "9.2.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAFA10BE-64D3-40D9-BA46-867A8345E90B",
              "versionEndExcluding": "9.1.0.26"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A57086A5-CF0C-4DCC-86D5-3159133CFF74",
              "versionEndIncluding": "9.2.1.6",
              "versionStartIncluding": "9.2.1.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "716AFCCC-1F9E-4C34-A02C-5924EF32BA23",
              "versionEndExcluding": "9.1.0.26"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "040B6E33-2F65-474F-9412-C9A4BBFD15FE",
              "versionEndExcluding": "9.2.1.6",
              "versionStartIncluding": "9.2.1.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43696C46-48E8-43E4-9387-77CE1B2BD401"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}