Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54h3-rfwf-3g76

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.

The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.

EPSS

Процентиль: 56%
0.00336
Низкий

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.

EPSS

Процентиль: 56%
0.00336
Низкий

Дефекты

CWE-276