QID 376375

QID 376375: Dell Unisphere for PowerMax Out-of-bounds Write Vulnerability

Unisphere for PowerMax offers big-button navigation and streamlined operations to simplify and reduce the time required to manage a data center.

CVE-2021-21548: Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an improper certificate validation vulnerability.

Affected Version:
Unisphere for PowerMax and Unisphere for PowerMax Virtual Appliance Versions prior to 9.1.0.27
Unisphere for PowerMax and Unisphere for PowerMax Virtual Appliance Versions prior to 9.2.1.8

QID Detection Logic:(Authenticated)
This QID checks the vulnerable version of Unisphere PowerMax via the EMC_SMAS_INSTALL_STATUS file.

Successful exploitation of this vulnerability may allow a local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Vendor has released fix to this vulnerability.

    Customers are advised to refer to DSA-2021-134 for more information.

    CVEs related to QID 376375

    Software Advisories
    Advisory ID Software Component Link
    DSA-2021-134 URL Logo www.dell.com/support/kbdoc/en-in/000189606/dsa-2021-134-dell-emc-unisphere-for-powermax-dell-emc-unisphere-for-powermax-virtual-appliance-dell-emc-solutions-enabler-virtual-appliance-and-dell-emc-powermax-embedded-management-security-update-for-multiple-third-party-component-vulnerabilities