CVE-2020-5328: Critical severity Dell EMC Isilon OneFS vulnerability
Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5328?
CVE-2020-5328 is a vulnerability in Dell EMC Isilon OneFS versions prior to 8.2.0 that allows unauthorized access and can result in loss of control of the cluster.
What is the severity of CVE-2020-5328?
CVE-2020-5328 has a severity rating of 9.8 (Critical).
How does CVE-2020-5328 occur?
CVE-2020-5328 occurs due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required.
Which software versions are affected by CVE-2020-5328?
Dell EMC Isilon OneFS versions prior to 8.2.0 are affected by CVE-2020-5328.
How can I fix CVE-2020-5328?
To fix CVE-2020-5328, update Dell EMC Isilon OneFS to version 8.2.0 or later.