CVE-2020-5328: Dell Emc Isilon Onefs

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.

Affected products

  • Dell Emc Isilon Onefs: before 8.2.0 (fixed in 8.2.0)

Published 2020-03-06. Last modified 2026-06-17.