Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-43589


Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the Unity underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.


Published

2022-01-24T20:15:08.227

Last Modified

2024-11-21T06:29:29.913

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_unity_operating_environment < 5.1.2.0.5.007 Yes
Application dell emc_unity_xt_operating_environment < 5.1.2.0.5.007 Yes
Application dell emc_unityvsa_operating_environment < 5.1.2.0.5.007 Yes

References