First published: Fri May 15 2020(Updated: )
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by default, with a pre-configured community string. This community string allows read-only access to many aspects of the Isilon cluster, some of which are considered sensitive and can foster additional access.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Isilon OneFS | <=8.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-5364 is high with a CVSS score of 7.5.
The affected software of CVE-2020-5364 is Dell EMC Isilon OneFS versions 8.2.2 and earlier.
CVE-2020-5364 affects Dell EMC Isilon OneFS by enabling the SNMPv2 service with a pre-configured community string, allowing read-only access to sensitive aspects of the Isilon cluster.
To fix CVE-2020-5364, it is recommended to update to a version of Dell EMC Isilon OneFS that is later than 8.2.2.
More information about CVE-2020-5364 can be found at the Dell EMC support website: https://www.dell.com/support/security/en-us/details/543775/DSA-2020-124-Dell-EMC-Isilon-OneFS-Security-Update-for-Multiple-Vulnerabilities