CVE-2020-26193: OS Command Injection
Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISIPRIVCLUSTER privilege may exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26193?
CVE-2020-26193 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2020-26193?
To fix CVE-2020-26193, you should upgrade Dell EMC PowerScale OneFS to the latest version that includes the security patch.
Which versions of Dell EMC PowerScale OneFS are affected by CVE-2020-26193?
CVE-2020-26193 affects Dell EMC PowerScale OneFS versions 8.1.0 to 9.1.0.
Who can exploit CVE-2020-26193?
A user with the ISI_PRIV_CLUSTER privilege can exploit CVE-2020-26193.
What does CVE-2020-26193 allow an attacker to do?
CVE-2020-26193 allows an attacker to execute arbitrary OS commands on the underlying OS of the application.