---
cve: "CVE-2017-14380"
severity: "LOW"
cvss: 3.1
epss: "35%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-12-13 20:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T02:36:39+02:00"
---

# CVE-2017-14380

> 3.1 LOW

## Beschreibung

In EMC Isilon OneFS 8.1.0.0, 8.0.1.0 - 8.0.1.1, 8.0.0.0 - 8.0.0.4, 7.2.1.0 - 7.2.1.5, 7.2.0.x, and 7.1.1.x, a malicious compliance admin (compadmin) account user could exploit a vulnerability in isi_get_itrace or isi_get_profile maintenance scripts to run any shell script as system root on a cluster in compliance mode. This could potentially lead to an elevation of privilege for the compadmin user and violate compliance mode.

## Referenzen

- <http://seclists.org/fulldisclosure/2017/Dec/41>
- <http://www.securityfocus.com/bid/102210>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-14380) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
