CVE-2018-1204: Path Traversal
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a path traversal vulnerability in the isiphonehome tool. A malicious compadmin may potentially exploit this vulnerability to execute arbitrary code with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1204?
CVE-2018-1204 is a path traversal vulnerability in the isi_phone_home tool in Dell EMC Isilon OneFS.
Which versions of Dell EMC Isilon OneFS are affected by CVE-2018-1204?
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, 8.0.0.0 - 8.0.0.6, 7.2.1.x, and 7.1.1.11 are affected.
How severe is CVE-2018-1204?
CVE-2018-1204 has a severity rating of 6.7 out of 10.
How can I fix the vulnerability in Dell EMC Isilon OneFS?
To fix the vulnerability, update Dell EMC Isilon OneFS to a version that is not affected.
Where can I find more information about CVE-2018-1204?
You can find more information about CVE-2018-1204 at the following links: [link1], [link2], [link3].