Server Side Request Forgery in Dell EMC Streaming Data Platform
CVE-2021-36327
5.3MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 30 November 2021
Summary
The Dell EMC Streaming Data Platform, prior to version 1.3, is affected by a Server Side Request Forgery vulnerability. This flaw allows remote unauthenticated attackers to potentially exploit the system, facilitating unauthorized port scanning of internal networks and making arbitrary HTTP requests to an attacker-controlled domain. Organizations using the affected versions should prioritize upgrading to mitigate this risk.
Affected Version(s)
Dell EMC Streaming Data Platform < 1.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved