CVE-2020-26192: High severity dell emc isilon onefs vulnerability
Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISIPRIVLOGINCONSOLE or ISIPRIVLOGINSSH may potentially exploit this vulnerability to read arbitrary data, tamper with system software or deny service to users. Note: no non-admin users or roles have these privileges by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26192?
CVE-2020-26192 has a critical severity level due to its potential for privilege escalation and impact on sensitive data.
How do I fix CVE-2020-26192?
To fix CVE-2020-26192, upgrade Dell EMC PowerScale OneFS to version 9.2.0 or later as recommended by Dell.
What types of attacks are possible due to CVE-2020-26192?
Exploitation of CVE-2020-26192 may allow a non-admin user to read arbitrary data, alter system software, or cause a denial of service.
Which versions of Dell EMC PowerScale OneFS are affected by CVE-2020-26192?
CVE-2020-26192 affects Dell EMC PowerScale OneFS versions 8.2.0 through 9.1.0.
Is CVE-2020-26192 being actively exploited?
As of the latest reports, there is no confirmation that CVE-2020-26192 is being actively exploited in the wild.