CVE-2020-26197
Published: 20 April 2021
Summary
CVE-2020-26197 is a high-severity Inadequate Encryption Strength (CWE-326) vulnerability in Dell Emc Powerscale Onefs. Its CVSS base score is 7.5 (High).
Operationally, ranked at the 32.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-18822
Vulnerability details
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not…
more
relying on an LDAP server for the authentication provider.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Establishment procedures require selection and generation of keys with adequate length and strength for the chosen algorithm.
Requires cryptography for transmission uses, eliminating cleartext exposure of sensitive data in transit.
Role-based training covers secure transmission methods, mitigating cleartext transmission of sensitive data.
By requiring documented security controls for information exchanges, the control reduces the risk of cleartext transmission of sensitive data.
Mapping transmission actions in data flows helps prevent cleartext transmission of sensitive information.
Settings can enforce secure transmission protocols to prevent cleartext transmission of sensitive data.
Policy addresses secure transport and handling of media to avoid cleartext transmission of sensitive information.
Maintaining currency with technologies and practices reduces selection of encryption mechanisms that provide inadequate strength.