Elevated Privilege Vulnerability in Dell EMC Isilon OneFS
CVE-2018-1203
6.7MEDIUM
What is CVE-2018-1203?
A vulnerability exists in Dell EMC Isilon OneFS that allows a user with compadmin privileges to execute the tcpdump binary with root privileges. Specifically, within certain versions, the misconfiguration permits the compadmin to run tcpdump with sudo, enabling the potential execution of arbitrary code at the root level. This flaw raises significant security concerns as it compromises the integrity of the system, providing unauthorized access to sensitive operations that should be restricted.
Affected Version(s)
Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, 8.0.0.0 - 8.0.0.6