CVE-2020-26180: High severity Dell EMC Isilon OneFS vulnerability
Published Jul 28, 2021
·Updated
Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols.
Affected Software
2 affected components
Dell EMC Isilon OneFS>=8.1.0
Dell EMC Powerscale OneFS=9.0.0
Event History
Jul 28, 2021
CVE Published
via MITRE·12:05 AM
Data Sourced
via MITRE·12:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26180?
The severity of CVE-2020-26180 is high.
2
Which versions of Dell EMC Isilon OneFS are affected by CVE-2020-26180?
Dell EMC Isilon OneFS supported versions 8.1 and later are affected by CVE-2020-26180.
3
Which version of Dell EMC PowerScale OneFS is affected by CVE-2020-26180?
Dell EMC PowerScale OneFS supported version 9.0.0 is affected by CVE-2020-26180.
4
What is the access issue in CVE-2020-26180?
CVE-2020-26180 has an access issue with the remotesupport user account.
5
How can a remote malicious user gain access to data in the /ifs directory?
A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols in CVE-2020-26180.