cbcvebase.

Dell Emc Powerscale Onefs vulnerabilities

84 known vulnerabilities affecting dell/emc_powerscale_onefs.

Total CVEs
84
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH33MEDIUM38LOW4

Vulnerabilities

Page 3 of 5
CVE-2023-25941P3HIGHCVSS 7.8≥ 9.1.0.0, ≤ 9.1.0.28≥ 9.2.1.0, < 9.2.1.22+1 more2023-04-04
CVE-2023-25941 [HIGH] CWE-276 CVE-2023-25941: Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability breaks the compliance mode guarantee.
nvd
CVE-2022-32480P3MEDIUMCVSS 6.5≥ 9.1.0.0, ≤ 9.1.0.19≥ 9.2.1.0, ≤ 9.2.1.12+2 more2022-08-22
CVE-2022-32480 [MEDIUM] CWE-1188 CVE-2022-32480: Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2021-21592P4MEDIUMCVSS 6.5≥ 9.0.0.0, ≤ 9.2.0v8.2.22021-08-16
CVE-2021-21592 [MEDIUM] CWE-755 CVE-2021-21592: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remot Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.
nvd
CVE-2022-45095P4MEDIUMCVSS 6.7≥ 9.1.0.0, < 9.1.0.25≥ 9.2.1.0, < 9.2.1.18+1 more2023-02-01
CVE-2022-45095 [MEDIUM] CWE-77 CVE-2022-45095: Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated use Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and data deletion.
nvd
CVE-2021-21599P4MEDIUMCVSS 6.7≥ 9.0.0.0, ≤ 9.2.1v8.2.22021-08-16
CVE-2021-21599 [MEDIUM] CWE-78 CVE-2021-21599: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. Th Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgra
nvd
CVE-2022-23159P4MEDIUMCVSS 6.5≥ 8.2.2, ≤ 9.3.02022-04-12
CVE-2022-23159 [MEDIUM] CWE-401 CVE-2022-23159: Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contain a missing release of memory after effective lifetime Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contain a missing release of memory after effective lifetime vulnerability. An authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE and ISI_PRIV_AUTH_PROVIDERS privileges could exploit this vulnerability, leading to a Denial-Of-Service. This can also impact a cluster in Compliance mode. Del
nvd
CVE-2023-25942P4MEDIUMCVSS 6.5≥ 9.1.0.0, ≤ 9.1.0.28≥ 9.2.1.0, < 9.2.1.22+2 more2023-04-04
CVE-2023-25942 [MEDIUM] CWE-664 CVE-2023-25942: Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerabili Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service.
nvd
CVE-2022-45096P4MEDIUMCVSS 6.5≥ 9.1.0.0, < 9.1.0.25≥ 9.2.1.0, < 9.2.1.18+1 more2023-02-01
CVE-2022-45096 [MEDIUM] CWE-355 CVE-2022-45096: Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenti Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information.
nvd
CVE-2020-26195P4MEDIUMCVSS 5.3v8.1.2v8.2.0+4 more2021-02-09
CVE-2020-26195 [MEDIUM] CWE-280 CVE-2020-26195: Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issue to slow down the system.
nvd
CVE-2022-34437P4MEDIUMCVSS 6.7≥ 9.1.0.0, ≤ 9.1.0.21≥ 9.2.1.0, ≤ 9.2.1.15+1 more2022-10-21
CVE-2022-34437 [MEDIUM] CWE-78 CVE-2022-34437: Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privil Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This impacts compliance mode clusters.
nvd
CVE-2021-36305P4MEDIUMCVSS 6.5v8.2.0v8.2.1+6 more2021-11-12
CVE-2021-36305 [MEDIUM] CWE-662 CVE-2021-36305: Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An authenticated user of SMB on a cluster with CA could potentially exploit this vulnerability, leading to a denial of service over SMB.
nvd
CVE-2021-21595P4MEDIUMCVSS 6.7≥ 9.0.0.0, < 9.2.0v8.2.22021-08-16
CVE-2021-21595 [MEDIUM] CWE-77 CVE-2021-21595: Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special ele Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunit
nvd
CVE-2021-21563P4MEDIUMCVSS 6.5v8.1.3v8.2.1+3 more2021-08-03
CVE-2021-21563 [MEDIUM] CWE-754 CVE-2021-21563: Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptiona Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.
nvd
CVE-2021-21550P4MEDIUMCVSS 6.7v8.1.1v8.1.2+4 more2021-05-06
CVE-2021-21550 [MEDIUM] CWE-78 CVE-2021-21550: Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability can allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.
nvd
CVE-2021-21527P4MEDIUMCVSS 6.7v9.0.0.0v9.1.0.02021-05-06
CVE-2021-21527 [MEDIUM] CWE-78 CVE-2021-21527: Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.
nvd
CVE-2016-1346P4MEDIUMCVSS 5.9v8.2.22016-04-06
CVE-2016-1346 [MEDIUM] CWE-399 CVE-2016-1346: The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673.
nvd
CVE-2023-25540P4HIGHCVSS 7.1≥ 9.4.0.0, ≤ 9.4.0.112023-02-28
CVE-2023-25540 [HIGH] CWE-276 CVE-2023-25540: Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local mali Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service.
nvd
CVE-2022-34454P4MEDIUMCVSS 6.7≥ 9.1.0.0, ≤ 9.1.0.20≥ 9.2.1.0, ≤ 9.2.1.13+1 more2023-02-10
CVE-2022-34454 [MEDIUM] CWE-122 CVE-2022-34454: Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privilege Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters.
nvd
CVE-2022-22550P4MEDIUMCVSS 6.7≥ 8.2.2, ≤ 9.3.02022-04-12
CVE-2022-22550 [MEDIUM] CWE-549 CVE-2022-22550: Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unp Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.
nvd
CVE-2020-5383P4MEDIUMCVSS 5.3v9.0.02020-08-27
CVE-2020-5383 [MEDIUM] CWE-119 CVE-2020-5383: Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer ov Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability in the Likewise component. A remote unauthenticated malicious attacker may potentially exploit this vulnerability to cause a process restart.
nvd
Dell Emc Powerscale Onefs vulnerabilities | cvebase