CVE Vulnerabilities

CVE-2017-14380

Improper Privilege Management

Published: Dec 13, 2017 | Modified: Oct 03, 2019
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In EMC Isilon OneFS 8.1.0.0, 8.0.1.0 - 8.0.1.1, 8.0.0.0 - 8.0.0.4, 7.2.1.0 - 7.2.1.5, 7.2.0.x, and 7.1.1.x, a malicious compliance admin (compadmin) account user could exploit a vulnerability in isi_get_itrace or isi_get_profile maintenance scripts to run any shell script as system root on a cluster in compliance mode. This could potentially lead to an elevation of privilege for the compadmin user and violate compliance mode.

Weakness

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Isilon_onefs Emc 7.1.1.0 7.1.1.0
Isilon_onefs Emc 7.1.1.1 7.1.1.1
Isilon_onefs Emc 7.1.1.2 7.1.1.2
Isilon_onefs Emc 7.1.1.3 7.1.1.3
Isilon_onefs Emc 7.1.1.4 7.1.1.4
Isilon_onefs Emc 7.1.1.5 7.1.1.5
Isilon_onefs Emc 7.2.0.0 7.2.0.0
Isilon_onefs Emc 7.2.0.1 7.2.0.1
Isilon_onefs Emc 7.2.0.2 7.2.0.2
Isilon_onefs Emc 7.2.0.3 7.2.0.3
Isilon_onefs Emc 7.2.0.4 7.2.0.4
Isilon_onefs Emc 7.2.0.5 7.2.0.5
Isilon_onefs Emc 7.2.1.0 7.2.1.0
Isilon_onefs Emc 7.2.1.1 7.2.1.1
Isilon_onefs Emc 7.2.1.2 7.2.1.2
Isilon_onefs Emc 7.2.1.3 7.2.1.3
Isilon_onefs Emc 7.2.1.4 7.2.1.4
Isilon_onefs Emc 7.2.1.5 7.2.1.5
Isilon_onefs Emc 8.0.0.0 8.0.0.0
Isilon_onefs Emc 8.0.0.1 8.0.0.1
Isilon_onefs Emc 8.0.0.2 8.0.0.2
Isilon_onefs Emc 8.0.0.3 8.0.0.3
Isilon_onefs Emc 8.0.0.4 8.0.0.4
Isilon_onefs Emc 8.0.1.0 8.0.1.0
Isilon_onefs Emc 8.0.1.1 8.0.1.1
Isilon_onefs Emc 8.1.0.0 8.1.0.0

Potential Mitigations

References