Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.
References
Configurations
History
21 Nov 2024, 05:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/security/en-us/details/541423/DSA-2020-039-Dell-EMC-Isilon-OneFS-Security-Update-for-a-SyncIQ-Vulnerability - Vendor Advisory |
Information
Published : 2020-03-06 21:15
Updated : 2024-11-21 05:33
NVD link : CVE-2020-5328
Mitre link : CVE-2020-5328
CVE.ORG link : CVE-2020-5328
JSON object : View
Products Affected
dell
- emc_isilon_onefs
CWE
CWE-306
Missing Authentication for Critical Function