Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-11071


Dell EMC Isilon OneFS versions 7.1.1.x, 7.2.1.x, 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 and Dell EMC IsilonSD Edge versions 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 contain a remote process crash vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the isi_drive_d process by sending specially crafted input data to the affected system. This process will then be restarted.


Published

2018-09-18T21:29:02.010

Last Modified

2024-11-21T03:42:37.277

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application emc isilon_onefs ≤ 7.1.1.11 Yes
Application emc isilon_onefs ≤ 7.2.1.6 Yes
Application emc isilon_onefs ≤ 8.0.0.7 Yes
Application emc isilon_onefs ≤ 8.0.1.2 Yes
Application emc isilon_onefs ≤ 8.1.0.4 Yes
Application emc isilon_onefs ≤ 8.1.2.0 Yes
Application emc isilonsd_edge ≤ 8.0.0.7 Yes
Application emc isilonsd_edge ≤ 8.0.1.2 Yes
Application emc isilonsd_edge < 8.1.2.0 Yes

References