{"api_version":"1","generated_at":"2026-07-23T14:24:09+00:00","cve":"CVE-2020-5355","urls":{"html":"https://cve.report/CVE-2020-5355","api":"https://cve.report/api/cve/CVE-2020-5355.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-5355","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-5355"},"summary":{"title":"CVE-2020-5355","description":"The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.","state":"PUBLIC","assigner":"secure@dell.com","published_at":"2022-10-21 18:15:00","updated_at":"2022-10-24 15:32:00"},"problem_types":["CWE-276"],"metrics":[],"references":[{"url":"https://support.emc.com/kb/543561","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-5355","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5355","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"5355","vulnerable":"1","versionEndIncluding":"8.2.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dell","cpe5":"emc_isilon_onefs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secure@dell.com","DATE_PUBLIC":"2021-11-23","ID":"CVE-2020-5355","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Isilon OneFS","version":{"version_data":[{"version_affected":"<","version_value":"8.2.2"}]}}]},"vendor_name":"Dell"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended."}]},"impact":{"cvss":{"baseScore":4.3,"baseSeverity":"Medium","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-276: Incorrect Default Permissions"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://support.emc.com/kb/543561","name":"https://support.emc.com/kb/543561"}]}},"nvd":{"publishedDate":"2022-10-21 18:15:00","lastModifiedDate":"2022-10-24 15:32:00","problem_types":["CWE-276"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dell:emc_isilon_onefs:*:*:*:*:*:*:*:*","versionEndIncluding":"8.2.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"5355","Ordinal":"165574","Title":"CVE-2020-5355","CVE":"CVE-2020-5355","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"5355","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}