CVE-2025-32753SQL Injection in Dell Powerscale Onefs

CWE-89SQL Injection3 documents3 sources
Severity
7.8HIGHNVD
CNA5.3
EPSS
0.1%
top 79.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 20

Description

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, information disclosure, and information tampering.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5dell/powerscale_onefs9.5.0.09.10.0.1
NVDdell/powerscale_onefs9.5.0.09.10.0.1

🔴Vulnerability Details

2
GHSA
GHSA-gwc8-g59x-m9xq: Dell PowerScale OneFS, versions 92025-06-20
CVEList
CVE-2025-32753: Dell PowerScale OneFS, versions 92025-06-20
CVE-2025-32753 — SQL Injection in Dell Powerscale Onefs | cvebase