Lucene search

K
cveDellCVE-2020-5365
HistoryMay 20, 2020 - 9:15 p.m.

CVE-2020-5365

2020-05-2021:15:10
CWE-330
CWE-341
dell
web.nvd.nist.gov
21
dell
emc
isilon
vulnerability
remotesupport
nvd
cve-2020-5365
onefs
account
predictable password

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

53.8%

Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other support functions. Although the default password is different for every cluster, it is predictable.

Affected configurations

Nvd
Vulners
Node
dellemc_isilon_onefsRange8.2.2
VendorProductVersionCPE
dellemc_isilon_onefs*cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Isilon OneFS",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "8.2.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

53.8%

Related for CVE-2020-5365