CVE-2021-36294
25.01.2022, 23:15
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.Enginsight
Vendor | Product | Version |
---|---|---|
dell | emc_unity_operating_environment | 𝑥 ≤ 8.1.21.266 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-331 - Insufficient EntropyThe software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
- CWE-330 - Use of Insufficiently Random ValuesThe software uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.