#VU59114 Command Injection in Dell products - CVE-2021-43589
Published: December 29, 2021
Vulnerability identifier: #VU59114
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-43589
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Software vendor:
Dell
Dell
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient input validation. A local privileged user can run a specially crafted command and escalate privileges on the system.
Remediation
Install updates from vendor's website.