CVE-2022-34371Insufficiently Protected Credentials in Dell Powerscale Onefs

Severity
9.8CRITICALNVD
CNA8.1
EPSS
0.5%
top 34.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 2
Latest updateSep 3

Description

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5dell/powerscale_onefsunspecified8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, 9.3.0.x. 9.4.0.x, 9.5.0.x
NVDdell/emc_powerscale_onefs9.1.0.09.1.0.19+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hr54-cp42-r2fp: Dell PowerScale OneFS, versions 92022-09-03
CVEList
CVE-2022-34371: Dell PowerScale OneFS, versions 92022-09-02