CVE-2018-1204 is a path traversal vulnerability in the isi_phone_home tool affecting multiple versions of Dell EMC Isilon OneFS. A highly privileged user (compadmin) could exploit this flaw to execute arbitrary code with root privileges. Rated Medium severity with a CVSS score of 6.7, the vulnerability requires local access but has high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, an ExploitDB entry exists, and it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.2.1.0, <= 7.2.1.6CPE matchmatch criteria | cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:* | ||
>= 8.0.0.0, <= 8.0.0.6CPE matchmatch criteria | cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:* | ||
>= 8.0.1.0, <= 8.0.1.2CPE matchmatch criteria | cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:* | ||
>= 8.1.0.0, <= 8.1.0.1CPE matchmatch criteria | cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:* | ||
7.1.1.11CPE matchmatch criteria | cpe:2.3:a:dell:emc_isilon_onefs:7.1.1.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.