cbcvebase.
CVE-2024-25959
published 2024-03-28

CVE-2024-25959: Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.16%
5.7th percentile
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.

Affected

7 ranges
VendorProductVersion rangeFixed in
dellpowerscale_onefs>= 9.4.0 < 9.4.0.179.4.0.17
dellpowerscale_onefs9.4.0.0 – 9.4.0.16
dellpowerscale_onefs>= 9.5.0.0 < 9.5.0.89.5.0.8
dellpowerscale_onefs9.5.0.0 – 9.5.0.7
dellpowerscale_onefs>= 9.6.1 < 9.7.0.29.7.0.2
dellpowerscale_onefs9.6.1.0 – 9.7.0.0
dellpowerscale_onefs9.7.0.0 – 9.7.0.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.