« Volver al listado

CVE-2021-36287

Estado: ModificadaCrítica (9.8)—

Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-36287",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "VNX2",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "Version 8.1.21.303 (file) Version 5.33.021.5.303 (block)",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-08T20:15:09.150",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000191155/dsa-2021-164-dell-vnx2-control-station-security-update-for-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000191155/dsa-2021-164-dell-vnx2-control-station-security-update-for-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system."
    },
    {
      "lang": "es",
      "value": "Dell VNX2 for file versión 8.1.21.266 y anteriores, contienen una vulnerabilidad de ejecución de código remota no autenticada que puede conllevar a usuarios no autenticados a ejecutar comandos en el sistema"
    }
  ],
  "lastModified": "2026-06-17T03:58:36.050",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:emc_unity_operating_environment:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCF2F423-762A-4FB0-9C78-665719437611",
              "versionEndIncluding": "8.1.21.266"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:vnx_vg10:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "97AAC263-26AA-46D3-99ED-1FC122680E9B"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx_vg50:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E6E09A30-8E1B-4FDE-9EAB-FD97297223E8"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8048D181-E5D8-434C-AEBD-F6AC5A39E196"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5400:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E0D31CA9-BA67-49D7-B079-43A78E15E9F7"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5600:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BF50C06E-3275-4DE3-9A1E-B713EC71BFE9"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E086C5AD-C7DC-4C8C-9690-58AB91BA4484"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx7600:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "69CB6012-801D-4A0E-B260-A056FBA2ECE9"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx8000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F02386BF-9508-4913-90E4-AEC7F3A7C5E1"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnxe1600:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FAF5AD8E-8B5E-4566-928F-FE67B3C100E1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}