Risky Cryptographic Algorithms in Dell EMC InsightIQ SSH Component
CVE-2021-36298

8.1HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
1 October 2021

Summary

Dell EMC InsightIQ versions before 4.1.4 are exposed to a vulnerability related to insecure cryptographic algorithms within the SSH component. This flaw allows remote unauthenticated attackers to potentially bypass authentication mechanisms, leading to unauthorized access and control over the InsightIQ system. It is crucial for users to upgrade to the latest version to mitigate risks and secure their environments against possible exploitation.

Affected Version(s)

Isilon InsightIQ < 4.1.4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.