ID

VAR-202102-0792


CVE

CVE-2021-21512


TITLE

Dell EMC PowerProtect Cyber Recovery  Information Disclosure Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2021-003878

DESCRIPTION

Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high privileged Cyber Recovery user may potentially exploit this vulnerability leading to the takeover of the notification email account. This vulnerability stems from configuration errors in network systems or products during operation. Thereby taking over the notification email account

Trust: 1.71

sources: NVD: CVE-2021-21512 // JVNDB: JVNDB-2021-003878 // VULHUB: VHN-379916

AFFECTED PRODUCTS

vendor:dellmodel:emc powerprotect cyber recoveryscope:eqversion:19.7.0.1

Trust: 1.0

vendor:デルmodel:powerprotect cyber recoveryscope:eqversion: -

Trust: 0.8

vendor:デルmodel:powerprotect cyber recoveryscope:eqversion:19.7.0.1

Trust: 0.8

sources: JVNDB: JVNDB-2021-003878 // NVD: CVE-2021-21512

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-21512
value: MEDIUM

Trust: 1.0

security_alert@emc.com: CVE-2021-21512
value: HIGH

Trust: 1.0

NVD: CVE-2021-21512
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202102-1403
value: MEDIUM

Trust: 0.6

VULHUB: VHN-379916
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2021-21512
severity: LOW
baseScore: 3.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-379916
severity: LOW
baseScore: 3.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-21512
baseSeverity: MEDIUM
baseScore: 6.0
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 0.8
impactScore: 5.2
version: 3.1

Trust: 1.0

security_alert@emc.com: CVE-2021-21512
baseSeverity: HIGH
baseScore: 7.9
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.5
impactScore: 5.8
version: 3.1

Trust: 1.0

NVD: CVE-2021-21512
baseSeverity: MEDIUM
baseScore: 6.0
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-379916 // JVNDB: JVNDB-2021-003878 // CNNVD: CNNVD-202102-1403 // NVD: CVE-2021-21512 // NVD: CVE-2021-21512

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.1

problemtype:information leak (CWE-200) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-379916 // JVNDB: JVNDB-2021-003878 // NVD: CVE-2021-21512

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202102-1403

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202102-1403

PATCH

title:DSA-2021-038url:https://www.dell.com/support/kbdoc/en-us/000183169/dsa-2021-038-dell-emc-powerprotect-cyber-recovery-security-update-for-unintended-information-disclosure

Trust: 0.8

title:Dell EMC PowerProtect Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=142840

Trust: 0.6

sources: JVNDB: JVNDB-2021-003878 // CNNVD: CNNVD-202102-1403

EXTERNAL IDS

db:NVDid:CVE-2021-21512

Trust: 2.5

db:JVNDBid:JVNDB-2021-003878

Trust: 0.8

db:CNNVDid:CNNVD-202102-1403

Trust: 0.7

db:VULHUBid:VHN-379916

Trust: 0.1

sources: VULHUB: VHN-379916 // JVNDB: JVNDB-2021-003878 // CNNVD: CNNVD-202102-1403 // NVD: CVE-2021-21512

REFERENCES

url:https://www.dell.com/support/kbdoc/en-us/000183169/dsa-2021-038-dell-emc-powerprotect-cyber-recovery-security-update-for-unintended-information-disclosure

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-21512

Trust: 1.4

sources: VULHUB: VHN-379916 // JVNDB: JVNDB-2021-003878 // CNNVD: CNNVD-202102-1403 // NVD: CVE-2021-21512

SOURCES

db:VULHUBid:VHN-379916
db:JVNDBid:JVNDB-2021-003878
db:CNNVDid:CNNVD-202102-1403
db:NVDid:CVE-2021-21512

LAST UPDATE DATE

2024-11-23T22:29:19.014000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-379916date:2021-02-25T00:00:00
db:JVNDBid:JVNDB-2021-003878date:2021-11-09T06:15:00
db:CNNVDid:CNNVD-202102-1403date:2021-03-01T00:00:00
db:NVDid:CVE-2021-21512date:2024-11-21T05:48:30.460

SOURCES RELEASE DATE

db:VULHUBid:VHN-379916date:2021-02-19T00:00:00
db:JVNDBid:JVNDB-2021-003878date:2021-11-09T00:00:00
db:CNNVDid:CNNVD-202102-1403date:2021-02-19T00:00:00
db:NVDid:CVE-2021-21512date:2021-02-19T17:15:13.577