PT-2021-11217 · Dell Emc · Dell Emc Isilon Onefs+1

Published

2021-01-05

·

Updated

2021-10-04

·

CVE-2020-26181

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dell EMC Isilon OneFS versions 8.1 and later Dell EMC PowerScale OneFS version 9.0.0
Description: The issue concerns a privilege escalation vulnerability on a SmartLock Compliance mode cluster. A compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV HARDENING privileges.
Recommendations: For Dell EMC Isilon OneFS versions 8.1 and later, consider restricting the ISI PRIV HARDENING privileges to prevent privilege escalation. For Dell EMC PowerScale OneFS version 9.0.0, restrict access to ISI PRIV LOGIN SSH and ISI PRIV LOGIN CONSOLE to minimize the risk of exploitation. As a temporary workaround, consider disabling the compadmin user's ability to connect using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE until a patch is available.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26181

Affected Products

Dell Emc Isilon Onefs
Dell Emc Powerscale Onefs