CVE-2020-5328: Dell Emc Isilon Onefs
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.
Affected products
- Dell Emc Isilon Onefs: before 8.2.0 (fixed in 8.2.0)
Published 2020-03-06. Last modified 2026-06-17.