← Back

CVE-2020-26191

nvd nist
Published: Feb 9, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the PermissionRepair job to grant themselves the highest level of RBAC privileges thus being able to read arbitrary data, tamper with system software or deny service to users.

Affected (8)

1 product
Emc Powerscale Onefs
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Dell
Version 8.1.0
Version 8.1.1
Version 8.1.2
Version 8.2.0
Version 8.2.1
Version 8.2.2
Version 9.0.0
Version 9.1.0

Timeline

No history available yet.