CVE-2020-5369Incorrect Permission Assignment in Dell Isilon Onefs

Severity
8.8HIGHNVD
EPSS
0.5%
top 35.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 2
Latest updateMay 24

Description

Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5dell/isilon_onefsunspecified8.1.2, 8.2.2, 9.0.0

🔴Vulnerability Details

2
GHSA
GHSA-cx2g-924g-69p7: Dell EMC Isilon OneFS versions 82022-05-24
CVEList
CVE-2020-5369: Dell EMC Isilon OneFS versions 82020-09-02
CVE-2020-5369 — Incorrect Permission Assignment in Dell | cvebase