Improper access control in 722 Series Ethernet Controllers and Adapters and 700 Series Ethernet Controllers and Adapters - CVE-2021-33126

 

Improper access control in 722 Series Ethernet Controllers and Adapters and 700 Series Ethernet Controllers and Adapters - CVE-2021-33126

Published: August 15, 2022


Vulnerability identifier: #VU66488
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33126
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the firmware. A local administrator can bypass implemented security restrictions and perform a denial of service (DoS) attack.


Affected software

722 Series Ethernet Controllers and Adapters
700 Series Ethernet Controllers and Adapters
Avamar Data Store Gen5A
PowerFlex Appliance
PowerFlex rack
EMC Integrated Data Protection Appliance
Precision 7920 Rack
VEP4600-16 Core
VEP4600-8 Core
VEP4600-4 Core

How to mitigate CVE-2021-33126

Install updates from vendor's website.

722 Series Ethernet Controllers and Adapters - update to 1.5.5
700 Series Ethernet Controllers and Adapters - update to 8.5
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
Precision 7920 Rack - update to 21.5.9
VEP4600-16 Core - update to 22.0.9
VEP4600-8 Core - update to 22.0.9
VEP4600-4 Core - update to 22.0.9

External References

Related Security Bulletins