Vulnerability Details CVE-2021-36349
Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.9%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2021-36349
-
cpe:2.3:a:dell:emc_data_protection_central:1.0
-
cpe:2.3:a:dell:emc_data_protection_central:1.0.1
-
cpe:2.3:a:dell:emc_data_protection_central:18.1
-
cpe:2.3:a:dell:emc_data_protection_central:18.2
-
cpe:2.3:a:dell:emc_data_protection_central:19.1
-
cpe:2.3:a:dell:emc_data_protection_central:19.3
-
cpe:2.3:a:dell:emc_data_protection_central:19.4
-
cpe:2.3:a:dell:emc_data_protection_central:19.5