### [CVE-2021-36278](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36278) ![](https://img.shields.io/static/v1?label=Product&message=PowerScale%20OneFS&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=8.2.x%2C%209.1.0.x%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-532%3A%20Information%20Exposure%20Through%20Log%20Files&color=brightgreen) ### Description Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges may exploit this vulnerability to access sensitive information. If any third-party consumes those logs, the same sensitive information is available to those systems as well. ### POC #### Reference - https://www.dell.com/support/kbdoc/000190408 #### Github No PoCs found on GitHub currently.