CVE-2020-26181
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/01/2021
Last modified:
04/10/2021
Description
Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV HARDENING privileges.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:* | 8.1.0.0 (including) | |
cpe:2.3:o:dell:emc_powerscale_onefs:9.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page