CVE-2020-26193

HIGH

Dell EMC PowerScale OneFS 8.1.0-9.1.0 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-20
Status published
Products (8)
dell/emc_powerscale_onefs 8.1.0
dell/emc_powerscale_onefs 8.1.1
dell/emc_powerscale_onefs 8.1.2
dell/emc_powerscale_onefs 8.2.0
dell/emc_powerscale_onefs 8.2.1
dell/emc_powerscale_onefs 8.2.2
dell/emc_powerscale_onefs 9.0.0
dell/emc_powerscale_onefs 9.1.0
Published Feb 09, 2021
Tracked Since Feb 18, 2026