Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5328

Опубликовано: 06 мар. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:*
Версия до 8.2.0 (исключая)

EPSS

Процентиль: 60%
0.00391
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-306
CWE-306

Связанные уязвимости

github
больше 3 лет назад

Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.

EPSS

Процентиль: 60%
0.00391
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-306
CWE-306