DSA-2020-093: Dell EMC Isilon OneFS and Dell EMC PowerScale OneFS Security Update for NFS Configuration Vulnerabilities

Resumen: Dell EMC Isilon OneFS and Dell EMC PowerScale OneFS remediation is available for NFS configuration vulnerability that could be exploited by malicious users to compromise the affected system. ...

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Impacto

High

Detalles

Summary:   
The home directory within Dell EMC Isilon OneFS and Dell EMC PowerScale OneFS requires a remediation to address a vulnerability.

  • Incorrect Default Permissions Vulnerability 

CVE-2020-5353

The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.

CVSS v3.1 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

  • Incorrect Default Permissions Vulnerability 

CVE-2020-5353

The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.

CVSS v3.1 Base Score: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Dell Technologies recomienda que todos los clientes tengan en cuenta tanto la puntuación base como cualquier otra puntuación ambiental y temporal relevante que pueda afectar la posible gravedad asociada con la vulnerabilidad de seguridad en particular.

Corrección y productos afectados

Affected products:    
Dell EMC Isilon OneFS versions 8.2.2 and earlier
Dell EMC PowerScale version 9.0.0

Remediation:     
For Dell EMC PowerScale OneFS version 9.0.0, the fix is contained in the release.
For Dell EMC Isilon OneFS version 8.2.2, the fix for this issue is included with the June 2020 Rollup Patch, as well as all future Rollup Patches. For more information and to obtain a Rollup patch, see the Current Isilon OneFS Patches document.
For Dell EMC Isilon OneFS version 8.2.1 and 8.1.2 the fix for this issue is included with the May 2020 Rollup Patch, as well as all future Rollup Patches.

Dell EMC recommends all customers upgrade at the earliest opportunity. 

Affected products:    
Dell EMC Isilon OneFS versions 8.2.2 and earlier
Dell EMC PowerScale version 9.0.0

Remediation:     
For Dell EMC PowerScale OneFS version 9.0.0, the fix is contained in the release.
For Dell EMC Isilon OneFS version 8.2.2, the fix for this issue is included with the June 2020 Rollup Patch, as well as all future Rollup Patches. For more information and to obtain a Rollup patch, see the Current Isilon OneFS Patches document.
For Dell EMC Isilon OneFS version 8.2.1 and 8.1.2 the fix for this issue is included with the May 2020 Rollup Patch, as well as all future Rollup Patches.

Dell EMC recommends all customers upgrade at the earliest opportunity. 

Soluciones alternativas y mitigaciones

CVE ID Workaround and Mitigations
CVE-2020-5353

Mitigation is required for any cluster with an NFS configuration that allows access to the admin user’s home directory, such as:

  • A cluster upgraded to a remediated version, retaining the default NFS configuration from the original installation

Example: A cluster installed using OneFS 8.0.0 with the default NFS configuration, and later upgraded to OneFS 9.0.0.

  • A cluster installed on a version where the /ifs NFS export was manually created and the NFS service was enabled.

Example: A cluster installed using OneFS 9.0.0 where the NFS export for /ifs was manually created and the NFS service enabled.

Note: Fresh installations of clusters using any remediated version have the NFS service disabled by default, and no /ifs NFS export is created. These installations do not require additional mitigation.

 

Mitigation

Apply one of the recommended mitigation steps to remediate this vulnerability:

 

Option 1: Disable NFS

  • Open an SSH connection to any node in the cluster.
  • Log in as root.
  • Disable NFS by running the following command:
isi services nfs disable

      

 

Option 2: Move the Admin Home Directory

 

Option 3: Configure Kerberos Authentication for NFS Access

  • Refer to the following sections of the Product CLI Administration Guide:   
    • Authentication chapter, Managing MIT Kerberos authentication section.
    • File sharing chapter, Managing NFS Exports section.

 

Reconocimientos

Dell would like to thank Knud from F-Secure for reporting this issue.

Información relacionada

Productos afectados

PowerScale OneFS

Productos

PowerScale OneFS, Product Security Information
Propiedades del artículo
Número del artículo: 000153867
Tipo de artículo: Dell Security Advisory
Última modificación: 09 abr 2026
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.