Description Preview
Dell EMC Isilon OneFS (versions 8.1 and later) and Dell EMC PowerScale OneFS (version 9.0.0) contain a vulnerability in the remotesupport user account that could allow a remote attacker with low privileges to gain unauthorized access to data stored in the /ifs directory through most protocols. This vulnerability is classified as CWE-276 (Incorrect Default Permissions).
Overview
This vulnerability (CVE-2020-26180) affects the remotesupport user account in Dell EMC Isilon OneFS (versions 8.1 and later) and Dell EMC PowerScale OneFS (version 9.0.0). The issue stems from incorrect default permissions that could allow a malicious user with low privileges to access data stored in the /ifs directory. The /ifs directory is typically the main storage location in Isilon and PowerScale systems, making this a significant security concern. The vulnerability allows access through most protocols supported by the system, potentially exposing sensitive data to unauthorized users.
Remediation
Organizations using affected Dell EMC Isilon OneFS or PowerScale OneFS systems should:
- Apply the security update provided by Dell EMC as detailed in DSA-2020-225
- Follow the specific installation instructions provided in the Dell EMC security advisory
- Review access logs for any suspicious activity related to the remotesupport account
- Audit user permissions across the system to identify any other potential permission issues
- Consider implementing additional access controls and monitoring for the /ifs directory
- Ensure that only necessary protocols are enabled on the system
References
- Dell EMC Security Advisory DSA-2020-225: https://www.dell.com/support/security/en-us/details/546591/DSA-2020-225-Dell-EMC-Isilon-OneFS-and-Dell-EMC-PowerScale-OneFS-Security-Update-for-remotesuppor
- CWE-276: Incorrect Default Permissions: https://cwe.mitre.org/data/definitions/276.html
- MITRE CVE Entry: CVE-2020-26180
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- ManufacturingManufacturing
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade