Vulnerability Description
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Isilon Onefs | <= 8.2.2 |
| Dell | Emc Powerscale Onefs | 9.0.0 |
Related Weaknesses (CWE)
References
- https://support.emc.com/kb/542721PatchVendor Advisory
- https://support.emc.com/kb/542721PatchVendor Advisory
FAQ
What is CVE-2020-5353?
CVE-2020-5353 is a vulnerability with a CVSS score of 8.8 (HIGH). The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker...
How severe is CVE-2020-5353?
CVE-2020-5353 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5353?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Emc Isilon Onefs, Dell Emc Powerscale Onefs.