CVE-2025-43937
published 2026-04-16CVE-2025-43937: Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with…
PriorityP429medium6.6CVSS 3.1
AVLACLPRLUIRSUCHINAH
EPSS
0.14%
3.8th percentile
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | powerscale_onefs | < 9.12.0.0 | 9.12.0.0 |
| dell | powerscale_onefs | < 9.5.1.5 | 9.5.1.5 |
| dell | powerscale_onefs | >= 9.11.0.0 < 9.12.0.0 | 9.12.0.0 |
| dell | powerscale_onefs | >= 9.5.0.0 < 9.10.1.3 | 9.10.1.3 |
| dell | powerscale_onefs | >= 9.5.0.0 < 9.5.1.5 | 9.5.1.5 |
| dell | powerscale_onefs | >= 9.6.0.0 < 9.7.1.10 | 9.7.1.10 |
| dell | powerscale_onefs | >= 9.7.0.0 < 9.7.1.9 | 9.7.1.9 |
| dell | powerscale_onefs | >= 9.8.0.0 < 9.10.1.3 | 9.10.1.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p7f2-6479-84wx: Dell PowerScale OneFS, versions prior to 9
ghsa_unreviewed·2026-04-16
CVE-2025-43937 [MEDIUM] CWE-532 GHSA-p7f2-6479-84wx: Dell PowerScale OneFS, versions prior to 9
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
VulDB
Dell PowerScale OneFS up to 9.12.0.0 log file (dsa-2025-347)
vuldb·2026-04-16·CVSS 6.6
CVE-2025-43937 [MEDIUM] Dell PowerScale OneFS up to 9.12.0.0 log file (dsa-2025-347)
A vulnerability has been found in Dell PowerScale OneFS up to 9.12.0.0 and classified as problematic. This issue affects some unknown processing. This manipulation causes sensitive information in log files.
This vulnerability is registered as CVE-2025-43937. The attack needs to be launched locally. No exploit is available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-16
Published