CVE-2021-36339 describes a critical vulnerability in Dell EMC Virtual Appliances, including PowerMax OS, Solutions Enabler, and Unisphere products, where undocumented user accounts exist. A local attacker could exploit this to gain privileged access to the virtual appliance, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 7.8 (High), this vulnerability is easily exploitable with low attack complexity and no user interaction required. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation have been observed, and community discussion is minimal, the presence of these backdoor accounts poses a significant security risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.1.0.18CPE matchmatch criteria | cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:* | ||
>= 9.2.0.0, < 9.2.3.0CPE matchmatch criteria | cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:* | ||
< 9.1.0.18CPE matchmatch criteria | cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:* | ||
>= 9.2.0.0, < 9.2.3.0CPE matchmatch criteria | cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:* | ||
< 9.1.0.29CPE matchmatch criteria | cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.