Dell EMC Isilon/OneFS RCE
Description
Dell EMC Isilon / OneFS is a scale-out network-attached storage (NAS), driven by the OneFS operating system.
In the default configuration the system supports NFS sharing. Due to a poorly mapped initial layout where the builtin admin user home directory is exposed via the default recommended /ifs share, and due to the inherent weaknesses in NFS where the system trusts the uid sent by the client, it is possible to modify contents in the home directory of the built-in admin user on the system.
Impact
Attackers on the network can map the /ifs resource as uid 10, the admin user, add an SSH key in /ifs/home/admin/.ssh/authorized_keys, and subsequently log in and execute arbitrary code on the system in this context. From this initial foothold a range of actions such as accessing data, removing drives from the storage array or other destructive options are also possible.