Dell Emc Powerscale Onefs vulnerabilities
84 known vulnerabilities affecting dell/emc_powerscale_onefs.
Total CVEs
84
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH33MEDIUM38LOW4
Vulnerabilities
Page 1 of 5
CVE-2022-22561P2CRITICALCVSS 9.8≥ 8.2.0, ≤ 9.3.02022-04-12
CVE-2022-22561 [CRITICAL] CWE-307 CVE-2022-22561: Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authenti
Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.
nvd
CVE-2022-45100P3CRITICALCVSS 9.8≥ 9.1.0.0, < 9.1.0.25≥ 9.2.1.0, < 9.2.1.18+2 more2023-02-01
CVE-2022-45100 [CRITICAL] CWE-295 CVE-2022-45100: Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerabil
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system.
nvd
CVE-2022-26852P3CRITICALCVSS 9.8≥ 8.2.0, ≤ 9.3.0.02022-04-08
CVE-2022-26852 [CRITICAL] CWE-337 CVE-2022-26852: Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number gene
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise.
nvd
CVE-2021-21502P3CRITICALCVSS 9.8v8.1.0v8.1.1+6 more2021-02-09
CVE-2021-21502 [CRITICAL] CWE-287 CVE-2021-21502: Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vuln
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially exploit this vulnerability, giving them access to the same things they had before account expiration. This may by a high privilege
nvd
CVE-2020-5369P3HIGHCVSS 8.8v9.0.02020-09-02
CVE-2020-5369 [HIGH] CWE-732 CVE-2020-5369: Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files.
nvd
CVE-2022-26854P3CRITICALCVSS 9.8≥ 8.2.0, ≤ 9.2.1.02022-04-08
CVE-2022-26854 [CRITICAL] CWE-327 CVE-2022-26854: Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unpriv
Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access
nvd
CVE-2022-34371P3CRITICALCVSS 9.8≥ 9.1.0.0, ≤ 9.1.0.19≥ 9.2.1.0, ≤ 9.2.1.12+2 more2022-09-02
CVE-2022-34371 [CRITICAL] CWE-522 CVE-2022-34371: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3,
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.
nvd
CVE-2020-26180P3HIGHCVSS 8.8v9.0.02021-07-28
CVE-2020-26180 [HIGH] CWE-276 CVE-2020-26180: Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported versi
Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols.
nvd
CVE-2020-5371P3HIGHCVSS 8.8v9.0.02020-07-06
CVE-2020-5371 [HIGH] CWE-732 CVE-2020-5371: Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a fil
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with network or local file access, could take advantage of insufficiently applied file permissions or gain unauthorized access to files.
nvd
CVE-2020-5353P3HIGHCVSS 8.8v9.0.02021-07-29
CVE-2020-5353 [HIGH] CWE-276 CVE-2020-5353: The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacker may leverage a spoofed Unique Identifier (UID) over NFS to rewrite sensitive files to gain administrative access to the system.
nvd
CVE-2022-45101P3CRITICALCVSS 9.8≥ 9.1.0.0, < 9.1.0.25≥ 9.2.1.0, < 9.2.1.18+1 more2023-02-01
CVE-2022-45101 [CRITICAL] CWE-274 CVE-2022-45101: Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges v
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution.
nvd
CVE-2021-36281P3HIGHCVSS 8.8≥ 9.0.0.0, ≤ 9.2.1v8.2.22021-08-16
CVE-2021-36281 [HIGH] CWE-732 CVE-2021-36281: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerab
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can potentially exploit this vulnerability to escalate privileges.
nvd
CVE-2022-24428P3HIGHCVSS 8.8≥ 8.2.0, ≤ 9.3.0.02022-04-08
CVE-2022-24428 [HIGH] CWE-281 CVE-2022-24428: Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an i
Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure.
nvd
CVE-2021-21506P3HIGHCVSS 8.8v8.1.2v8.2.2+1 more2021-03-08
CVE-2021-21506 [HIGH] CWE-20 CVE-2021-21506: PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API hand
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vulnerability, leading to potential privileges escalation.
nvd
CVE-2022-26851P3CRITICALCVSS 9.1≥ 8.2.2, ≤ 9.3.0.02022-04-08
CVE-2022-26851 [CRITICAL] CWE-330 CVE-2022-26851: Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerabi
Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.
nvd
CVE-2020-26197P3CRITICALCVSS 9.1v8.1.0v8.1.1+2 more2021-04-20
CVE-2020-26197 [CRITICAL] CWE-326 CVE-2020-26197: Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vuln
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the authentication provider.
nvd
CVE-2022-45097P3HIGHCVSS 8.8≥ 9.1.0.0, < 9.1.0.25≥ 9.2.1.0, < 9.2.1.18+1 more2023-02-01
CVE-2022-45097 [HIGH] CWE-842 CVE-2022-45097: Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low pr
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure.
nvd
CVE-2023-22575P3HIGHCVSS 8.8≥ 9.1.0.0, < 9.1.0.27≥ 9.2.1.0, < 9.2.1.20+1 more2023-02-01
CVE-2023-22575 [HIGH] CWE-532 CVE-2023-22575: Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges.
nvd
CVE-2022-22549P3HIGHCVSS 8.1≥ 8.2.0, ≤ 9.3.02022-04-12
CVE-2022-22549 [HIGH] CWE-295 CVE-2022-22549: Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated re
Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials.
nvd
CVE-2020-26193P3HIGHCVSS 7.8v8.1.0v8.1.1+6 more2021-02-09
CVE-2020-26193 [HIGH] CWE-20 CVE-2020-26193: Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability.
Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.
nvd
1 / 5Next →