PT-2021-11217 · Dell Emc · Dell Emc Isilon Onefs+1
Published
2021-01-05
·
Updated
2021-10-04
·
CVE-2020-26181
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Dell EMC Isilon OneFS versions 8.1 and later
Dell EMC PowerScale OneFS version 9.0.0
Description:
The issue concerns a privilege escalation vulnerability on a SmartLock Compliance mode cluster. A
compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV HARDENING privileges.Recommendations:
For Dell EMC Isilon OneFS versions 8.1 and later, consider restricting the
ISI PRIV HARDENING privileges to prevent privilege escalation.
For Dell EMC PowerScale OneFS version 9.0.0, restrict access to ISI PRIV LOGIN SSH and ISI PRIV LOGIN CONSOLE to minimize the risk of exploitation.
As a temporary workaround, consider disabling the compadmin user's ability to connect using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE until a patch is available.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Isilon Onefs
Dell Emc Powerscale Onefs