PT-2020-18434 · Dell Emc · Synciq+2

Published

2020-09-02

·

Updated

2020-09-11

·

CVE-2020-5369

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Isilon OneFS versions 8.2.2 and earlier Dell EMC PowerScale OneFS version 9.0.0
Description The issue allows an authenticated malicious user to exploit a privilege escalation vulnerability, potentially gaining unauthorized access to system management files by using SyncIQ.
Recommendations For Dell EMC Isilon OneFS versions 8.2.2 and earlier, update to a version later than 8.2.2 to resolve the issue. For Dell EMC PowerScale OneFS version 9.0.0, update to a version later than 9.0.0 to resolve the issue.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5369

Affected Products

Dell Emc Isilon Onefs
Dell Emc Powerscale Onefs
Synciq