QID 730118
Date Published: 2021-06-28
QID 730118: Dell Unisphere for PowerMax Security Update for Multiple Third-Party Component Vulnerabilities
Unisphere for PowerMax offers big-button navigation and streamlined operations to simplify and reduce the time required to manage a data center.
CVE-2021-21531: Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability
Affected Version:
Unisphere for PowerMax and Unisphere for PowerMax Virtual Appliance Versions prior to 9.1.0.26
Unisphere for PowerMax and Unisphere for PowerMax Virtual Appliance Versions prior to 9.2.1.6
QID Detection Logic:(Unauthenticated)
This QID sends a GET request to find if the target is running a vulnerable version of Unisphere PowerMax.
Successful exploitation of this vulnerability may allow a local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
Customers are advised to refer to DSA-2021-063 for more information.