CVE-2021-21588
Last modified
CVE-2021-21588 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Powerflex Presentation Server | >= 3.5, < 3.6 |
References
- https://www.dell.com/support/kbdoc/000189265Vendor Advisory
- https://www.dell.com/support/kbdoc/000189265Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21588?
How severe is CVE-2021-21588?
How do I fix CVE-2021-21588?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-21580Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRA…4.3
- CVE-2021-21581Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross…6.1
- CVE-2021-21584Dell OpenManage Enterprise version 3.5 and OpenManage Enterp…6.5
- CVE-2021-21585Dell OpenManage Enterprise versions prior to 3.6.1 contain a…7.2
- CVE-2021-21586Wyse Management Suite versions 3.2 and earlier contain an ab…6.5
- CVE-2021-21587Dell Wyse Management Suite versions 3.2 and earlier contain …3.3
- CVE-2021-21589Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1…6.7
- CVE-2021-2159Vulnerability in the PeopleSoft Enterprise CS Campus Communi…3.5
- CVE-2021-21590Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1…6.7
- CVE-2021-21591Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1…6.7
- CVE-2021-21592Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly …6.5
- CVE-2021-21594Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use…5.3
Are you affected by CVE-2021-21588?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
