CVE-2021-36298

HIGH

Dell EMC InsightIQ <4.1.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potentially exploit this vulnerability leading to authentication bypass and remote takeover of the InsightIQ. This allows an attacker to take complete control of InsightIQ to affect services provided by SSH; so Dell recommends customers to upgrade at the earliest opportunity.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.dell.com/support/kbdoc/000191604

Scores

CVSS v3 8.1
EPSS 0.0020
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-327
Status published
Products (1)
dell/isilon_insightiq_firmware < 4.1.4
Published Oct 01, 2021
Tracked Since Feb 18, 2026