Dell Emc Powerscale Onefs vulnerabilities
84 known vulnerabilities affecting dell/emc_powerscale_onefs.
Total CVEs
84
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH33MEDIUM38LOW4
Vulnerabilities
Page 4 of 5
CVE-2022-34438P4MEDIUMCVSS 6.7≥ 9.1.0.0, ≤ 9.1.0.22≥ 9.2.1.0, ≤ 9.2.1.15+2 more2022-10-21
CVE-2022-34438 [MEDIUM] CWE-269 CVE-2022-34438: Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.
nvd
CVE-2022-33932P4MEDIUMCVSS 5.3≥ 9.1.0.0, ≤ 9.1.0.19≥ 9.2.1.0, ≤ 9.2.1.12+2 more2022-08-22
CVE-2022-33932 [MEDIUM] CWE-419 CVE-2022-33932: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2,
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotected primary channel vulnerability. An unauthenticated network malicious attacker may potentially exploit this vulnerability, leading to a denial of filesystem services.
nvd
CVE-2021-21594P4MEDIUMCVSS 5.3≥ 9.0.0.0, ≤ 9.1.0v8.2.22021-08-16
CVE-2021-21594 [MEDIUM] CWE-598 CVE-2021-21594: Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive qu
Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.
nvd
CVE-2020-26196P4MEDIUMCVSS 5.5v8.1.0v8.1.1+6 more2021-02-09
CVE-2020-26196 [MEDIUM] CWE-732 CVE-2020-26196: Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation iss
Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentially exploit this vulnerability resulting in the ability to write data outside of the intended file system location.
nvd
CVE-2021-36280P4MEDIUMCVSS 5.5≥ 9.0.0.0, ≤ 9.2.1v8.2.22021-08-16
CVE-2021-36280 [MEDIUM] CWE-732 CVE-2021-36280: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for crit
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster.
nvd
CVE-2022-31238P4MEDIUMCVSS 5.5≥ 9.1.0.0, ≤ 9.1.0.19≥ 9.2.1.0, ≤ 9.2.1.12+2 more2022-08-22
CVE-2022-31238 [MEDIUM] CWE-200 CVE-2022-31238: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2,
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive information vulnerability. A CLI user may potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2022-45098P4MEDIUMCVSS 5.5≥ 9.1.0.0, < 9.1.0.25≥ 9.2.1.0, < 9.2.1.18+1 more2023-02-01
CVE-2022-45098 [MEDIUM] CWE-532 CVE-2022-45098: Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulner
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2021-36278P4MEDIUMCVSS 5.5≥ 8.2.0, ≤ 8.2.2≥ 9.0.0.0, ≤ 9.1.0+2 more2021-08-16
CVE-2021-36278 [MEDIUM] CWE-532 CVE-2021-36278: Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information expos
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges may exploit this vulnerability to access sensitive information. If any third-party consumes those logs, the same
nvd
CVE-2021-21561P4MEDIUMCVSS 5.5v8.1.2v8.2.2+3 more2021-11-23
CVE-2021-21561 [MEDIUM] CWE-532 CVE-2021-21561: Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This wo
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.
nvd
CVE-2022-22560P4MEDIUMCVSS 5.5≥ 8.1.0, ≤ 9.2.1.02022-04-12
CVE-2022-22560 [MEDIUM] CWE-798 CVE-2022-22560: Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user wit
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch offline.
nvd
CVE-2023-22573P4MEDIUMCVSS 5.5≥ 9.1.0.0, < 9.1.0.27≥ 9.2.1.0, < 9.2.1.20+1 more2023-02-01
CVE-2023-22573 [MEDIUM] CWE-532 CVE-2023-22573: Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vu
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.
nvd
CVE-2022-34378P4MEDIUMCVSS 5.5≥ 9.1.0.0, ≤ 9.1.0.20≥ 9.2.1.0, ≤ 9.2.1.13+2 more2022-09-02
CVE-2022-34378 [MEDIUM] CWE-23 CVE-2022-34378: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3,
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2021-21568P4MEDIUMCVSS 4.3≥ 9.0.0.0, ≤ 9.2.1v8.2.22021-08-16
CVE-2021-21568 [MEDIUM] CVE-2021-21568: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An a
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An authenticated user with ISI_PRIV_LOGIN_PAPI could make un-audited and un-trackable configuration changes to settings that their roles have privileges to change.
nvd
CVE-2022-33934P4MEDIUMCVSS 4.8≥ 9.1.0.0, ≤ 9.1.0.23≥ 9.2.1.0, ≤ 9.2.1.16+2 more2023-02-10
CVE-2022-33934 [MEDIUM] CWE-79 CVE-2022-33934: Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vu
Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected fields.
nvd
CVE-2022-23160P4MEDIUMCVSS 4.3≥ 8.2.2, ≤ 9.3.02022-04-12
CVE-2022-23160 [MEDIUM] CWE-274 CVE-2022-23160: Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissio
Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious user could potentially exploit this vulnerability, leading to gaining write permissions on read-only files.
nvd
CVE-2022-26855P4MEDIUMCVSS 5.5≥ 8.2.0, ≤ 9.3.0.02022-04-08
CVE-2022-26855 [MEDIUM] CWE-276 CVE-2022-26855: Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerabili
Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability, leading to a denial of service.
nvd
CVE-2022-23163P4MEDIUMCVSS 5.5≥ 8.2.2, ≤ 9.3.02022-04-12
CVE-2022-23163 [MEDIUM] CWE-379 CVE-2022-23163: Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerabilit
Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious user could potentially exploit this vulnerability, leading to denial of service/data unavailability.
nvd
CVE-2022-31239P4MEDIUMCVSS 4.4≥ 9.1.0.0, ≤ 9.1.0.19≥ 9.2.1.0, ≤ 9.2.1.12+1 more2022-10-21
CVE-2022-31239 [MEDIUM] CWE-532 CVE-2022-31239: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain s
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.
nvd
CVE-2021-21562P4MEDIUMCVSS 4.4v8.1.2v8.1.3+2 more2021-08-03
CVE-2021-21562 [MEDIUM] CWE-426 CVE-2021-21562: Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application’s direct control.
nvd
CVE-2022-22563P4MEDIUMCVSS 4.4≥ 8.2.0, ≤ 9.3.0.02022-04-08
CVE-2022-22563 [MEDIUM] CWE-223 CVE-2022-22563: Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A
Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.
nvd