Vulnerability Details CVE-2020-5328
Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2020-5328
-
cpe:2.3:a:dell:emc_isilon_onefs:7.1.1.11
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.0
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.1
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.2
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.3
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.4
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.5
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.6
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.0
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.1
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.2
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.3
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.4
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.5
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.6
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.7
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.1.0
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.1.1
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.1.2
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.0
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.1
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.2
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.3
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.4
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.2