PT-2021-12398 · Dell+1 · Dell Isilon Onefs+1

Published

2021-07-29

·

Updated

2021-08-06

·

CVE-2020-5353

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell Isilon OneFS versions 8.2.2 and earlier Dell EMC PowerScale OneFS version 9.0.0
Description The default configuration for Network File System (NFS) in the affected software allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files and gain administrative access to the system.
Recommendations For Dell Isilon OneFS versions 8.2.2 and earlier, restrict access to the 'admin' home directory to prevent unauthorized access. For Dell EMC PowerScale OneFS version 9.0.0, consider disabling the default NFS configuration to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of NFS until a patch is available.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5353

Affected Products

Dell Emc Powerscale Onefs
Dell Isilon Onefs