CVE-2020-5365
20.05.2020, 21:15
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other support functions. Although the default password is different for every cluster, it is predictable.Enginsight
Vendor | Product | Version |
---|---|---|
dell | emc_isilon_onefs | 𝑥 ≤ 8.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-341 - Predictable from Observable StateA number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.
- CWE-330 - Use of Insufficiently Random ValuesThe software uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.