PT-2018-10952 · Dell Emc · Isilon Onefs

Ivan Huertas

+1

·

Publicado

2018-03-26

·

Atualizado

2019-10-03

·

CVE-2018-1203

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell EMC Isilon OneFS versions 8.0.0.0 through 8.0.0.6 Dell EMC Isilon OneFS versions 8.0.1.0 through 8.0.1.2 Dell EMC Isilon OneFS versions 8.1.0.0 through 8.1.0.1
Description The issue allows the compadmin to run the tcpdump binary with root privileges. This could potentially be used to execute arbitrary code with root privileges.
Recommendations For versions 8.0.0.0 through 8.0.0.6, consider restricting the use of the tcpdump binary to prevent potential exploitation. For versions 8.0.1.0 through 8.0.1.2, consider restricting the use of the tcpdump binary to prevent potential exploitation. For versions 8.1.0.0 through 8.1.0.1, consider restricting the use of the tcpdump binary to prevent potential exploitation.

Exploit

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1203

Produtos afetados

Isilon Onefs