cve/2021/CVE-2021-36278.md
2025-09-29 21:09:30 +02:00

18 lines
970 B
Markdown

### [CVE-2021-36278](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36278)
![](https://img.shields.io/static/v1?label=Product&message=PowerScale%20OneFS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=8.2.x%2C%209.1.0.x%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-532%3A%20Information%20Exposure%20Through%20Log%20Files&color=brightgreen)
### Description
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges may exploit this vulnerability to access sensitive information. If any third-party consumes those logs, the same sensitive information is available to those systems as well.
### POC
#### Reference
- https://www.dell.com/support/kbdoc/000190408
#### Github
No PoCs found on GitHub currently.