CVE-2020-5328
Last modified
CVE-2020-5328 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.. EPSS estimates a 1.39% chance of exploitation in the next 30 days.
Description
Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Isilon Onefs | < 8.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5328?
How severe is CVE-2020-5328?
How do I fix CVE-2020-5328?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-5321Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 a…7.6
- CVE-2020-5322Dell EMC OpenManage Enterprise-Modular (OME-M) versions prio…9.1
- CVE-2020-5323Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 a…8.1
- CVE-2020-5324Dell Client Consumer and Commercial Platforms contain an Arb…4.4
- CVE-2020-5326Affected Dell Client platforms contain a BIOS Setup configur…5.3
- CVE-2020-5327Dell Security Management Server versions prior to 10.2.10 co…9.8
- CVE-2020-5329Dell EMC Avamar Server contains an open redirect vulnerabili…6.1
- CVE-2020-5330Dell EMC Networking X-Series firmware versions 3.0.1.2 and o…7.5
- CVE-2020-5331RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an i…5.5
- CVE-2020-5332RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a co…7.2
- CVE-2020-5333RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an a…4.3
- CVE-2020-5334RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a D…6.1
Are you affected by CVE-2020-5328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
