PT-2022-9046 · Dell · Dell Isilon Onefs
Published
2022-10-21
·
Updated
2022-10-24
·
CVE-2020-5355
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell Isilon OneFS versions 8.2.2 and earlier
Description
The SSHD process in Dell Isilon OneFS improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.
Recommendations
For versions 8.2.2 and earlier, consider restricting access to the SSHD process to minimize the risk of exploitation.
As a temporary workaround, consider disabling TCP and stream forwarding in the SSHD process until a patch is available.
Restrict access to the remotesupport user and users with restricted shells to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Isilon Onefs