Executive brief
EMC Isilon OneFS, the operating system for Isilon scale-out storage solutions, is vulnerable to a security flaw that could allow an authorized user to gain unauthorized control over the system. By exploiting a weakness in how the system handles directory service queries, a malicious actor with existing high-level access could potentially compromise the entire storage environment. This could lead to unauthorized data access or disruption of storage services.
Technical details
An LDAP injection vulnerability (CWE-90) exists in multiple versions of EMC Isilon OneFS. The flaw stems from improper neutralization of special elements used in LDAP queries, allowing an attacker to manipulate the logic of directory service requests. According to the CVSS metrics, the attack vector is local and requires high privileges (PR:H), suggesting that an attacker must already have significant access to the system to execute the exploit. Successful exploitation could lead to a full compromise of the system's confidentiality, integrity, and availability.
Affected products
- EMC OneFS 8.0.0.0, 7.2.1.0 - 7.2.1.2, 7.2.0.x, 7.1.1.0 - 7.1.1.10, 7.1.0.x
Timeline
- 2017-01-23: advisory: Initial NVD publication