QID 730356
Date Published: 2022-02-15
QID 730356: Dell Unisphere for PowerMax Out-of-bounds Write Vulnerability
Unisphere for PowerMax offers big-button navigation and streamlined operations to simplify and reduce the time required to manage a data center.
CVE-2021-21548: Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an improper certificate validation vulnerability.
Affected Version:
Unisphere for PowerMax and Unisphere for PowerMax Virtual Appliance Versions prior to 9.1.0.27
Unisphere for PowerMax and Unisphere for PowerMax Virtual Appliance Versions prior to 9.2.1.8
QID Detection Logic:(Unauthenticated)
This QID sends a GET request to find if the target is running a vulnerable version of Unisphere PowerMax.
Successful exploitation of this vulnerability may allow a local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
Customers are advised to refer to DSA-2021-134 for more information.