PT-2021-11221 · Dell Emc · Dell Emc Powerscale Onefs
Published
2021-02-09
·
Updated
2021-02-12
·
CVE-2020-26193
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Dell EMC PowerScale OneFS versions 8.1.0 through 9.1.0
Description:
The issue is related to improper input validation, allowing a user with the
ISI PRIV CLUSTER privilege to execute arbitrary OS commands on the application's underlying OS with the privileges of the vulnerable application.Recommendations:
For Dell EMC PowerScale OneFS versions 8.1.0 through 9.1.0, consider restricting the
ISI PRIV CLUSTER privilege to minimize the risk of exploitation until a patch is available.Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Emc Powerscale Onefs