← back
CVE-2021-36313

CVE-2021-36313

CVSS 9.1 CRITICALEPSS 2.1%CWE-74
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 2.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
23 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it may be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
Dell · CloudLink

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →