cbcvebase.

Dell Powerscale Onefs vulnerabilities

174 known vulnerabilities affecting dell/powerscale_onefs.

Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8

Vulnerabilities

Page 1 of 9
CVE-2024-53298P2CRITICALCVSS 9.8≥ 9.5.0.0, ≤ 9.10.0.12025-06-20
CVE-2024-53298 [CRITICAL] CWE-862 CVE-2024-53298: Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerabi Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be able to read, modify, and delete arbitrary files. This vulnerability i
nvd
CVE-2026-22278P2CRITICALCVSS 9.8fixed in 9.13.0.0≥ N/A, < 9.13.0.02026-01-22
CVE-2026-22278 [CRITICAL] CWE-307 CVE-2026-22278: Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authe Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2025-27690P2CRITICALCVSS 9.8≥ 9.5.0.0, ≤ 9.10.1.0≥ 9.6.0.0, ≤ 9.7.1.6+3 more2025-04-10
CVE-2025-27690 [CRITICAL] CWE-1393 CVE-2025-27690: Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnera Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.
nvd
CVE-2022-22561P2CRITICALCVSS 9.8v8.2.x-9.3.0.x2022-04-12
CVE-2022-22561 [CRITICAL] CWE-307 CVE-2022-22561: Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authenti Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.
nvd
CVE-2022-45100P3CRITICALCVSS 9.8≥ 8.2.x, ≤ 9.3.x2023-02-01
CVE-2022-45100 [CRITICAL] CWE-295 CVE-2022-45100: Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerabil Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system.
nvd
CVE-2022-26852P3CRITICALCVSS 9.8≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x , 9.2.1.x, 9.3.0.x2022-04-08
CVE-2022-26852 [CRITICAL] CWE-337 CVE-2022-26852: Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number gene Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise.
nvd
CVE-2021-21502P3CRITICALCVSS 9.8≥ unspecified, < 8.1.2 / 8.2.2 / 9.1.0.x / Empire / Main2021-02-09
CVE-2021-21502 [CRITICAL] CWE-287 CVE-2021-21502: Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vuln Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially exploit this vulnerability, giving them access to the same things they had before account expiration. This may by a high privilege
nvd
CVE-2022-31230P3CRITICALCVSS 9.8≥ 8.2.0, < 9.3.0≥ unspecified, < 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, 9.3.0.x2022-06-28
CVE-2022-31230 [CRITICAL] CWE-327 CVE-2022-31230: Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm. A remo Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access.
nvd
CVE-2022-26854P3CRITICALCVSS 9.8≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x2022-04-08
CVE-2022-26854 [CRITICAL] CWE-327 CVE-2022-26854: Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unpriv Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access
nvd
CVE-2022-34371P3CRITICALCVSS 9.8≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, 9.3.0.x. 9.4.0.x, 9.5.0.x2022-09-02
CVE-2022-34371 [CRITICAL] CWE-522 CVE-2022-34371: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.
nvd
CVE-2020-26180P3HIGHCVSS 8.8≥ unspecified, < OneFS 8.1.2, 8.2.2, 9.0+2021-07-28
CVE-2020-26180 [HIGH] CWE-276 CVE-2020-26180: Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported versi Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most protocols.
nvd
CVE-2023-32457P3HIGHCVSS 8.8≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+4 more2023-08-29
CVE-2023-32457 [HIGH] CWE-267 CVE-2023-32457: Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerab Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2022-45101P3CRITICALCVSS 9.8≥ 9.0.0.x, ≤ 9.4.0.x2023-02-01
CVE-2022-45101 [CRITICAL] CWE-274 CVE-2022-45101: Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges v Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution.
nvd
CVE-2021-36350P3HIGHCVSS 7.5≥ 8.2.2, < 9.3.1.0v8.2.2-9.3.0.x)2021-12-21
CVE-2021-36350 [HIGH] CWE-287 CVE-2021-36350: Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote unauthenticated attacker may potentially exploit this vulnerability and bypass one of the factors of authentication.
nvd
CVE-2021-36281P3HIGHCVSS 8.8v8.2.x - 9.2.x2021-08-16
CVE-2021-36281 [HIGH] CWE-732 CVE-2021-36281: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerab Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can potentially exploit this vulnerability to escalate privileges.
nvd
CVE-2022-24428P3HIGHCVSS 8.8≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, 9.3.0.x2022-04-08
CVE-2022-24428 [HIGH] CWE-281 CVE-2022-24428: Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an i Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure.
nvd
CVE-2021-21506P3HIGHCVSS 8.8≥ unspecified, < 8.1.2, 8.2.2,9.1.0.x,EMPIRE (9.2.0), GOTHAM2021-03-08
CVE-2021-21506 [HIGH] CWE-20 CVE-2021-21506: PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API hand PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vulnerability, leading to potential privileges escalation.
nvd
CVE-2024-22463P3CRITICALCVSS 9.1≥ 8.2.0, < 9.4.0.17≥ 9.5.0.0, < 9.5.0.6+4 more2024-03-04
CVE-2024-22463 [CRITICAL] CWE-327 CVE-2024-22463: Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algori Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to compromise of confidentiality and integrity of sensitive information
nvd
CVE-2026-22279P3HIGHCVSS 7.5fixed in 9.13.0.0≥ N/A, < 9.13.0.02026-01-22
CVE-2026-22279 [HIGH] CWE-778 CVE-2026-22279: Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An u Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
nvd
CVE-2022-26851P3CRITICALCVSS 9.1≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.1.1.x (Super Tubes), 9.2.0.x (Empire), 9.2.1.x (Flying Scotsman), 9.3.0.x (Gotham),2022-04-08
CVE-2022-26851 [CRITICAL] CWE-330 CVE-2022-26851: Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerabi Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.
nvd
Dell Powerscale Onefs vulnerabilities | cvebase