Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

DSA-2020-142: Dell EMC Isilon OneFS and Dell EMC PowerScale OneFS Security Update for SyncIQ Privilege Escalation Vulnerability with /ifs/.ifsvar directory

This article applies to   This article does not apply to 

Impact

Critical

Details

Summary:      
Dell EMC Isilon OneFS and Dell EMC PowerScale OneFS contain a remediation for a SyncIQ privilege escalation that may be exploited by malicious users to compromise the affected system.

  • Privilege Escalation Vulnerability

Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files.

CVSS v3.1 Base Score: 8.8 (/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

  • Privilege Escalation Vulnerability

Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files.

CVSS v3.1 Base Score: 8.8 (/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:      
Dell EMC Isilon OneFS versions 8.2.2 and earlier.
Dell EMC PowerScale OneFS version 9.0.0.


Resolution:      
For Dell EMC Isilon OneFS versions 8.2.2 and 8.1.2, the fix for this issue is included with the August, 2020 Roll-up Patch, as well as all future Roll-up Patches.

For Dell EMC PowerScale OneFS version 9.0.0, the fix for this issue is included with the August, 2020 Roll-up Patch, as well as all future Roll-up Patches.

For more information and to obtain a Roll-up patch, see the Current PowerScale and Isilon OneFS Patches document.

Affected products:      
Dell EMC Isilon OneFS versions 8.2.2 and earlier.
Dell EMC PowerScale OneFS version 9.0.0.


Resolution:      
For Dell EMC Isilon OneFS versions 8.2.2 and 8.1.2, the fix for this issue is included with the August, 2020 Roll-up Patch, as well as all future Roll-up Patches.

For Dell EMC PowerScale OneFS version 9.0.0, the fix for this issue is included with the August, 2020 Roll-up Patch, as well as all future Roll-up Patches.

For more information and to obtain a Roll-up patch, see the Current PowerScale and Isilon OneFS Patches document.

Related Information

Affected Products

PowerScale OneFS

Product

PowerScale OneFS, Product Security Information
Article Properties
Article Number: 000153709
Article Type: Dell Security Advisory
Last Modified: 22 May 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.
Article Properties
Article Number: 000153709
Article Type: Dell Security Advisory
Last Modified: 22 May 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.