Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

DSA-2021-123: Dell PowerScale OneFS Security Update for multiple vulnerabilities

Summary: Dell PowerScale OneFS remediation is available for multiple vulnerabilities that may be exploited by malicious users to compromise the affected system.

This article applies to   This article does not apply to 

Impact

Critical

Details

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2021-21567 Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege. Since this also affects Compliance mode, this is a critical vulnerability and Dell recommends upgrading at the earliest opportunity. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
 
Third-party Component CVE More information
Python CVE-2021-3177 See Advisory: Python Issue 42938  
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2021-21567 Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege. Since this also affects Compliance mode, this is a critical vulnerability and Dell recommends upgrading at the earliest opportunity. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
 
Third-party Component CVE More information
Python CVE-2021-3177 See Advisory: Python Issue 42938  
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs Addressed  Affected Versions Updated Versions Link to Update
CVE-2021-3177 8.1.x, 8.2x, 9.0.0.x, and 9.2.0 Upgrade your version of OneFS

PowerScale Downloads Area
8.1.2, 8.2.2, and 9.1.0.x Download and install the relevant GA-RUP_2021-06
CVE-2021-21567 9.0.0.x Upgrade your version of OneFS
9.1.0.x Download and install the relevant GA-RUP_2021-06
CVEs Addressed  Affected Versions Updated Versions Link to Update
CVE-2021-3177 8.1.x, 8.2x, 9.0.0.x, and 9.2.0 Upgrade your version of OneFS

PowerScale Downloads Area
8.1.2, 8.2.2, and 9.1.0.x Download and install the relevant GA-RUP_2021-06
CVE-2021-21567 9.0.0.x Upgrade your version of OneFS
9.1.0.x Download and install the relevant GA-RUP_2021-06

Revision History

RevisionDateDescription
1.02021-07-12Initial Release

Related Information

Affected Products

PowerScale OneFS, Product Security Information
Article Properties
Article Number: 000189495
Article Type: Dell Security Advisory
Last Modified: 15 Feb 2022
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.
Article Properties
Article Number: 000189495
Article Type: Dell Security Advisory
Last Modified: 15 Feb 2022
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.