Lucene search

K
cvelistDellCVELIST:CVE-2020-26180
HistoryJul 28, 2021 - 12:05 a.m.

CVE-2020-26180

2021-07-2800:05:13
CWE-276
dell
www.cve.org
7
cve-2020-26180
dell emc
isilon onefs
powerscale onefs
access issue
remote user
low privileges
data access

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

42.8%

Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols.

CNA Affected

[
  {
    "product": "PowerScale OneFS",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "OneFS 8.1.2, 8.2.2, 9.0+",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVELIST:CVE-2020-26180