PT-2020-18404 · Dell Emc · Dell Emc Isilon Onefs

Published

2020-03-06

·

Updated

2020-03-09

·

CVE-2020-5328

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell EMC Isilon OneFS versions prior to 8.2.0
Description The issue is related to unauthorized access due to insufficient authorization checks when SyncIQ is licensed but encrypted syncs are not marked as required, potentially leading to loss of control of the cluster.
Recommendations For versions prior to 8.2.0, update to version 8.2.0 or later to resolve the issue.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5328

Affected Products

Dell Emc Isilon Onefs