CVE-2022-34378Relative Path Traversal in Dell Powerscale Onefs

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 86.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 2
Latest updateSep 3

Description

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5dell/powerscale_onefsunspecified8.2.x, 9.0.0.x, 9.1.0.x, 9.1.1.x, 9.2.0.x, 9.2.1.x, 9.3.0.x. 9.4.0.x, 9.5.0.x
NVDdell/emc_powerscale_onefs9.1.0.09.1.0.20+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8mm7-v538-f52q: Dell PowerScale OneFS, versions 92022-09-03
CVEList
CVE-2022-34378: Dell PowerScale OneFS, versions 92022-09-02
CVE-2022-34378 — Relative Path Traversal in Dell | cvebase