CSV injection in Broadcom products - CVE-2021-22035
Published: October 13, 2021
Vulnerability identifier: #VU57322
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22035
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary code into CSV files.
The vulnerability exists due to improper input validation in interactive analytics export function. A remote authenticated attacker can inject arbitrary code into a CSV file.
Affected software
Cloud Foundation (vRLI)
Dell Enterprise Hybrid Cloud
vRealize Suite Lifecycle Manager
Aria Operations for Logs (formerly vRealize Log Insight)
Dell Enterprise Hybrid Cloud
vRealize Suite Lifecycle Manager
Aria Operations for Logs (formerly vRealize Log Insight)
How to mitigate CVE-2021-22035
Install updates from vendor's website.
Aria Operations for Logs (formerly vRealize Log Insight) - addressed in versions 8.1.1 18457068, 8.2.0 18430722, 8.4.1 18603443
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell Enterprise Hybrid Cloud - update to 4.1.2