CVE-2020-5347: High severity Dell EMC Isilon OneFS vulnerability
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell EMC Isilon OneFSto a version that resolves this vulnerability.Fixed in 8.2.2 - Compensating control
Mitigate the SmartConnect denial-of-service condition by preventing/avoiding the SmartConnect error condition that can loop and consume CPU, to ensure SmartConnect DNS responses are not blocked.
Event History
Frequently Asked Questions
What is CVE-2020-5347?
CVE-2020-5347 is a denial of service vulnerability in Dell EMC Isilon OneFS versions 8.2.2 and earlier.
How does CVE-2020-5347 affect Dell EMC Isilon OneFS?
CVE-2020-5347 can be exploited to trigger a looping error condition in SmartConnect, consuming CPU resources and potentially affecting SmartConnect DNS responses.
What is the severity of CVE-2020-5347?
CVE-2020-5347 has a severity value of 7.5 (High).
How can I fix CVE-2020-5347?
To fix CVE-2020-5347, update Dell EMC Isilon OneFS to version 8.2.3 or later.
Where can I find more information about CVE-2020-5347?
You can find more information about CVE-2020-5347 at the following link: [Dell EMC Isilon OneFS Security Update for DNS Protocol Vulnerabilities](https://www.dell.com/support/security/en-us/details/542190/DSA-2020-054-Dell-EMC-Isilon-OneFS-Security-Update-for-DNS-Protocol-Vulnerabilities).