PT-2021-12398 · Dell+1 · Dell Isilon Onefs+1
Published
2021-07-29
·
Updated
2021-08-06
·
CVE-2020-5353
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell Isilon OneFS versions 8.2.2 and earlier
Dell EMC PowerScale OneFS version 9.0.0
Description
The default configuration for Network File System (NFS) in the affected software allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files and gain administrative access to the system.
Recommendations
For Dell Isilon OneFS versions 8.2.2 and earlier, restrict access to the 'admin' home directory to prevent unauthorized access.
For Dell EMC PowerScale OneFS version 9.0.0, consider disabling the default NFS configuration to minimize the risk of exploitation.
As a temporary workaround, consider restricting the use of NFS until a patch is available.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Powerscale Onefs
Dell Isilon Onefs