PT-2021-11225 · Dell · Dell Powerscale Onefs

Published

2021-04-20

·

Updated

2022-10-21

·

CVE-2020-26197

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Dell PowerScale OneFS versions 8.1.0 through 9.1.0
Description: The issue is related to the LDAP Provider's inability to connect over TLSv1.2, which may make it easier for a malicious actor to eavesdrop and decrypt traffic. This issue does not affect clusters that are not relying on an LDAP server for the authentication provider.
Recommendations: For Dell PowerScale OneFS versions 8.1.0 through 9.1.0, consider configuring the LDAP connection to use a secure protocol or updating the authentication provider configuration to mitigate the risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2020-26197

Affected Products

Dell Powerscale Onefs