Dell Emc Isilon vulnerabilities

7 known vulnerabilities affecting dell/emc_isilon.

Total CVEs
7
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2020-5383MEDIUMCVSS 5.3v8.2.22020-08-27
CVE-2020-5383 [MEDIUM] CWE-119 CVE-2020-5383: Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer ov Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability in the Likewise component. A remote unauthenticated malicious attacker may potentially exploit this vulnerability to cause a process restart.
nvd
CVE-2018-1186MEDIUMCVSS 4.8PoC≥ 7.2.1.0, ≤ 7.2.1.6≥ 8.0.0.0, ≤ 8.0.0.6+3 more2018-03-26
CVE-2018-1186 [MEDIUM] CWE-79 CVE-2018-1186: Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versio Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's br
nvd
CVE-2018-1189MEDIUMCVSS 4.8PoC≥ 7.2.1.0, ≤ 7.2.1.6≥ 8.0.0.0, ≤ 8.0.0.6+3 more2018-03-26
CVE-2018-1189 [MEDIUM] CWE-79 CVE-2018-1189: Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versio Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Antivirus Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's bro
nvd
CVE-2018-1187MEDIUMCVSS 4.8PoC≥ 8.0.0.0, ≤ 8.0.0.6≥ 8.0.1.0, ≤ 8.0.1.2+1 more2018-03-26
CVE-2018-1187 [MEDIUM] CWE-79 CVE-2018-1187: Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affe Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerability in the Network Configuration page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context
nvd
CVE-2018-1202MEDIUMCVSS 4.8PoC≥ 8.0.0.0, ≤ 8.0.0.6≥ 8.0.1.0, ≤ 8.0.1.2+2 more2018-03-26
CVE-2018-1202 [MEDIUM] CWE-79 CVE-2018-1202: Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and ve Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the con
nvd
CVE-2018-1188MEDIUMCVSS 4.8PoC≥ 7.2.1.0, ≤ 7.2.1.6≥ 8.0.0.0, ≤ 8.0.0.6+2 more2018-03-26
CVE-2018-1188 [MEDIUM] CWE-79 CVE-2018-1188: Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and ve Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripting vulnerability in the Authorization Providers page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser
nvd
CVE-2018-1201MEDIUMCVSS 4.8PoC≥ 8.0.0.0, ≤ 8.0.0.6≥ 8.0.1.0, ≤ 8.0.1.2+2 more2018-03-26
CVE-2018-1201 [MEDIUM] CWE-79 CVE-2018-1201: Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versio Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Job Operations Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user'
nvd