CVE-2020-5364

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
20/05/2020
Last modified:
21/05/2020

Description

Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by default, with a pre-configured community string. This community string allows read-only access to many aspects of the Isilon cluster, some of which are considered sensitive and can foster additional access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:* 8.2.2 (including)