First published: Sat Jul 04 2015(Updated: )
The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Isilon OneFS | <=7.1.1.0 | |
Dell EMC Isilon OneFS | =7.1.1.1 | |
Dell EMC Isilon OneFS | =7.1.1.2 | |
Dell EMC Isilon OneFS | =7.1.1.3 | |
Dell EMC Isilon OneFS | =7.1.1.4 | |
Dell EMC Isilon OneFS | =7.2.0.0 | |
Dell EMC Isilon OneFS | =7.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4525 is considered a critical vulnerability because it allows remote authenticated users to execute arbitrary commands with root privileges.
To fix CVE-2015-4525, upgrade EMC Isilon OneFS to versions 7.1.1.5 or later, or 7.2.0.2 or later.
CVE-2015-4525 affects users of EMC Isilon OneFS versions 6.5.x.x through 7.1.1.4 and 7.2.0.0 through 7.2.0.1.
CVE-2015-4525 potentially provides attackers with root access to the system, allowing full control over the affected environment.
CVE-2015-4525 was disclosed in July 2015.