CVE-2021-36318
Linux Gentoo vulnerability analysis and mitigation

Overview

Dell EMC Avamar versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain a plain-text password storage vulnerability identified as CVE-2021-36318. The vulnerability was disclosed in July 2021 and affects multiple Dell EMC products including Avamar Server, PowerProtect Data Protection Appliance (IDPA), and related systems running on SUSE Linux Enterprise (Dell Advisory).

Technical details

The vulnerability is classified as a plain-text password storage vulnerability with a CVSS Base Score of 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). The vulnerability requires high privileges for exploitation and has local access vector requirements (Dell Advisory).

Impact

If exploited, this vulnerability could lead to a complete outage of the affected system. The high privileged user could potentially exploit this vulnerability to gain unauthorized access to stored credentials and system information (Dell Advisory).

Mitigation and workarounds

Dell has released security updates to address this vulnerability. Users are advised to upgrade to the latest versions: 18.2.x, 19.1.x, 19.2.x, 19.3.x, or 19.4.x with the OS rollup 2021-R2 or the latest OS rollup. Installation instructions are available in KB article 69982 for applying the hotfix (Dell Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Gentoo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13470HIGH7.7
  • Linux DebianLinux Debian
  • rnp
NoYesNov 21, 2025
CVE-2025-65018HIGH7.1
  • NixOSNixOS
  • libpng-devel
NoYesNov 25, 2025
CVE-2025-64720HIGH7.1
  • NixOSNixOS
  • libpng16-16-x86-64-v3
NoYesNov 25, 2025
CVE-2025-64506MEDIUM6.1
  • NixOSNixOS
  • libpng-debuginfo
NoYesNov 25, 2025
CVE-2025-64505MEDIUM6.1
  • NixOSNixOS
  • java-1.8.0-openjdk-javadoc
NoYesNov 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management