Improper Neutralization of Special Elements in Output Used by a Downstream Component in iDRAC9 - CVE-2021-36348
Published: August 8, 2022
Vulnerability identifier: #VU66170
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36348
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information or perform a denial of service attack.
The vulnerability exists due to an unspecified error in iDRAC9. A remote usee can exploit this vulnerability to gain access to sensitive information or perform a denial of service attack.
Affected software
iDRAC9
Dell EMC VxRail Appliance
PowerScale OneFS
Integrated System for Microsoft Azure Stack Hub
Dell EMC VxRail Appliance
PowerScale OneFS
Integrated System for Microsoft Azure Stack Hub
How to mitigate CVE-2021-36348
Install updates from vendor's website.
iDRAC9 - update to 5.00.20.00
Dell EMC VxRail Appliance - update to 7.0.350
PowerScale OneFS - update to 11.7
Integrated System for Microsoft Azure Stack Hub - update to 2207
Dell EMC VxRail Appliance - update to 7.0.350
PowerScale OneFS - update to 11.7
Integrated System for Microsoft Azure Stack Hub - update to 2207