CVE Vulnerabilities

CVE-2020-5365

Predictable from Observable State

Published: May 20, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other support functions. Although the default password is different for every cluster, it is predictable.

Weakness

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

Affected Software

Name Vendor Start Version End Version
Emc_isilon_onefs Dell * 8.2.2 (including)

Potential Mitigations

References