Vulnerability Details CVE-2020-5364
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by default, with a pre-configured community string. This community string allows read-only access to many aspects of the Isilon cluster, some of which are considered sensitive and can foster additional access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.2%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-5364
-
cpe:2.3:a:dell:emc_isilon_onefs:7.1.1.11
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.0
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.1
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.2
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.3
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.4
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.5
-
cpe:2.3:a:dell:emc_isilon_onefs:7.2.1.6
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.0
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.1
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.2
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.3
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.4
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.5
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.6
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.0.7
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.1.0
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.1.1
-
cpe:2.3:a:dell:emc_isilon_onefs:8.0.1.2
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.0
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.1
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.2
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.3
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.0.4
-
cpe:2.3:a:dell:emc_isilon_onefs:8.1.2
-
cpe:2.3:a:dell:emc_isilon_onefs:8.2.0
-
cpe:2.3:a:dell:emc_isilon_onefs:8.2.2