PT-2020-18399 · Dell Emc · Dell Emc Isilon Onefs

Published

2020-02-06

·

Updated

2020-02-11

·

CVE-2020-5318

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC Isilon OneFS versions 8.0.0.7, 8.1.0.3, 8.1.0.4, and 8.1.2
Description The issue allows an attacker to gain access to restricted files in certain configurations. This is due to a vulnerability in the non-RAN HTTP and WebDAV file-serving components when either is enabled and Basic Authentication is enabled for either or both components, resulting in files being accessible without authentication.
Recommendations For versions 8.0.0.7, 8.1.0.3, 8.1.0.4, and 8.1.2, consider disabling the non-RAN HTTP and WebDAV file-serving components or disabling Basic Authentication for these components to minimize the risk of exploitation. Restrict access to sensitive files until a fix is available.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5318

Affected Products

Dell Emc Isilon Onefs