Vulnerability Details CVE-2020-26194
Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This may allow a non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to exploit the vulnerability, leading to compromised cryptographic operations. Note: no non-admin users or roles have these privileges by default.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.3%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 4.6
Products affected by CVE-2020-26194
-
cpe:2.3:o:dell:emc_powerscale_onefs:8.1.2
-
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.2