HIGH🇵🇱 Wersja polska

CVE-2020-5353

CVSS 8.8v3.1pub. 2021-07-29upd. 2024-11-21

The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Dell Emc Isilon Onefs

    APP
    Dell
    ≤ 8.2.2
  • Dell Emc Powerscale Onefs

    OS
    Dell
    9.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-26851CRITICAL9.1PL ✓same product

Dell PowerScale OneFS — przewidywalna nazwa pliku umożliwia utratę danych

CVE-2021-21502CRITICAL9.8PL ✓same product

Dell PowerScale OneFS — pominięcie wygaśnięcia konta przez klucz SSH

CVE-2020-5328CRITICAL9.8PL ✓same product

Dell EMC Isilon OneFS — nieautoryzowany dostęp przez SyncIQ (brak szyfrowania)

CVE-2023-25941HIGH7.8same product

Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privilege...

CVE-2022-33934HIGH7.7same product

Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilit...