CVE-2020-5318 is a vulnerability in Dell Emc Isilon Onefs
Published on February 6, 2020
Dell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit this vulnerability to gain access to restricted files. The non-RAN HTTP and WebDAV file-serving components have a vulnerability wherein when either are enabled, and Basic Authentication is enabled for either or both components, files are accessible without authentication.
Vulnerability Analysis
CVE-2020-5318 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2020-5318 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2020-5318
Want to know whenever a new CVE is published for Dell Emc Isilon Onefs? stack.watch will email you.
Affected Versions
Dell Isilon OneFS Version 8.1.2, 8.1.0.4, 8.1.0.3, 8.0.0.7 is affected by CVE-2020-5318Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.