CVE-2020-26191

Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the PermissionRepair job to grant themselves the highest level of RBAC privileges thus being able to read arbitrary data, tamper with system software or deny service to users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:dell:emc_powerscale_onefs:8.1.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.1.1:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.1.2:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.1:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.2:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:9.0.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:9.1.0:*:*:*:*:*:*:*

History

14 Sep 2021, 18:17

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-noinfo

12 Feb 2021, 17:02

Type Values Removed Values Added
References (MISC) https://www.dell.com/support/kbdoc/en-us/000182873/dsa-2021-009-dell-powerscale-onefs-security-update-for-multiple-vulnerabilities - (MISC) https://www.dell.com/support/kbdoc/en-us/000182873/dsa-2021-009-dell-powerscale-onefs-security-update-for-multiple-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CPE cpe:2.3:o:dell:emc_powerscale_onefs:8.2.1:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:9.0.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.1.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.1.2:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.1.1:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:9.1.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerscale_onefs:8.2.2:*:*:*:*:*:*:*
CWE CWE-269

09 Feb 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-09 22:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-26191

Mitre link : CVE-2020-26191

CVE.ORG link : CVE-2020-26191


JSON object : View

Products Affected

dell

  • emc_powerscale_onefs
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management