« Volver al listado

CVE-2021-36293

Estado: ModificadaMedia (6.7)—

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-36293",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "VNX2",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "Version 8.1.21.303 (file) Version 5.33.021.5.303 (block)",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-08T20:15:09.387",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000191155/dsa-2021-164-dell-vnx2-control-station-security-update-for-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000191155/dsa-2021-164-dell-vnx2-control-station-security-update-for-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges."
    },
    {
      "lang": "es",
      "value": "Dell VNX2 for File versión 8.1.21.266 y anteriores, contienen una vulnerabilidad de escalada de privilegios. Un administrador local malicioso podría explotar la vulnerabilidad y alcanzar altos privilegios"
    }
  ],
  "lastModified": "2026-06-17T03:58:36.500",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:emc_unity_operating_environment:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCF2F423-762A-4FB0-9C78-665719437611",
              "versionEndIncluding": "8.1.21.266"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:vnx_vg10:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "97AAC263-26AA-46D3-99ED-1FC122680E9B"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx_vg50:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E6E09A30-8E1B-4FDE-9EAB-FD97297223E8"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8048D181-E5D8-434C-AEBD-F6AC5A39E196"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5400:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E0D31CA9-BA67-49D7-B079-43A78E15E9F7"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5600:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BF50C06E-3275-4DE3-9A1E-B713EC71BFE9"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx5800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E086C5AD-C7DC-4C8C-9690-58AB91BA4484"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx7600:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "69CB6012-801D-4A0E-B260-A056FBA2ECE9"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnx8000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F02386BF-9508-4913-90E4-AEC7F3A7C5E1"
            },
            {
              "criteria": "cpe:2.3:h:dell:vnxe1600:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FAF5AD8E-8B5E-4566-928F-FE67B3C100E1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}