CVE-2022-22563Omission of Security-relevant Information in Dell Powerscale Onefs

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 87.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8
Latest updateApr 9

Description

Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5dell/powerscale_onefsunspecified9.3.0.x
NVDdell/emc_powerscale_onefs8.2.09.3.0.0

🔴Vulnerability Details

2
GHSA
GHSA-wcf3-m96w-97fg: Dell EMC Powerscale OneFS 82022-04-09
CVEList
CVE-2022-22563: Dell EMC Powerscale OneFS 82022-04-08
CVE-2022-22563 — Dell Powerscale Onefs vulnerability | cvebase