PT-2020-18404 · Dell Emc · Dell Emc Isilon Onefs
Published
2020-03-06
·
Updated
2020-03-09
·
CVE-2020-5328
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell EMC Isilon OneFS versions prior to 8.2.0
Description
The issue is related to unauthorized access due to insufficient authorization checks when SyncIQ is licensed but encrypted syncs are not marked as required, potentially leading to loss of control of the cluster.
Recommendations
For versions prior to 8.2.0, update to version 8.2.0 or later to resolve the issue.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Isilon Onefs