CVE-2024-25959Log File Information Exposure in Dell Powerscale Onefs

Severity
5.5MEDIUMNVD
CNA7.9
EPSS
0.1%
top 75.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 28

Description

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDdell/powerscale_onefs9.4.09.4.0.17+2
CVEListV5dell/powerscale_onefs9.4.0.09.4.0.16+3

🔴Vulnerability Details

2
CVEList
CVE-2024-25959: Dell PowerScale OneFS versions 92024-03-28
GHSA
GHSA-5c87-f5rm-hwpp: Dell PowerScale OneFS versions 92024-03-28
CVE-2024-25959 — Log File Information Exposure in Dell | cvebase