Vulnerability Details CVE-2021-21549
Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to the vulnerable application, causing unintended server operations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.1%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2021-21549
-
cpe:2.3:a:dell:xtremio_management_server:-
-
cpe:2.3:a:dell:xtremio_management_server:6.3.0
-
cpe:2.3:h:dell:xtremio_x1:-
-
cpe:2.3:h:dell:xtremio_x2:-