Dell Powerscale Onefs vulnerabilities
174 known vulnerabilities affecting dell/powerscale_onefs.
Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8
Vulnerabilities
Page 2 of 9
CVE-2020-26197P3CRITICALCVSS 9.1v8.1.0-9.1.02021-04-20
CVE-2020-26197 [CRITICAL] CWE-326 CVE-2020-26197: Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vuln
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the authentication provider.
nvd
CVE-2022-45097P3HIGHCVSS 8.8≥ 9.0.0.x, ≤ 9.4.0.x2023-02-01
CVE-2022-45097 [HIGH] CWE-842 CVE-2022-45097: Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low pr
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure.
nvd
CVE-2023-32493P3CRITICALCVSS 9.8≥ 9.5.0.0, ≤ 9.5.0.3vVersion 9.5.0.0 through 9.5.0.32023-08-16
CVE-2023-32493 [CRITICAL] CWE-693 CVE-2023-32493: Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileg
Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.
nvd
CVE-2023-22575P3HIGHCVSS 8.8≤ 9.1.0.0 through 9.1.0.262023-02-01
CVE-2023-22575 [HIGH] CWE-532 CVE-2023-22575: Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges.
nvd
CVE-2025-43723P3HIGHCVSS 7.5fixed in 9.10.1.3≥ 9.11.0.0, < 9.12.0.0+2 more2025-11-10
CVE-2025-43723 [HIGH] CWE-327 CVE-2025-43723: Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a
Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2022-22549P3HIGHCVSS 8.1v8.2.x-9.3.x2022-04-12
CVE-2022-22549 [HIGH] CWE-295 CVE-2022-22549: Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated re
Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials.
nvd
CVE-2023-44295P3HIGHCVSS 8.1≥ 8.2.2, ≤ 9.6.0vVersion 8.2.2.x through 9.6.0.x2023-12-05
CVE-2023-44295 [HIGH] CWE-664 CVE-2023-44295: Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource t
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.
nvd
CVE-2025-36601P3HIGHCVSS 7.5≥ 9.8.0.0, < 9.10.1.3≥ 9.5.0.0, < 9.5.1.4+2 more2025-09-25
CVE-2025-36601 [HIGH] CWE-200 CVE-2025-36601: Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive informat
Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2021-21553P3HIGHCVSS 8.8≥ 8.1.0, ≤ 9.1.0v8.1.0-9.1.02021-08-03
CVE-2021-21553 [HIGH] CWE-286 CVE-2021-21553: Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under
Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading at the earliest.
nvd
CVE-2022-29098P3HIGHCVSS 7.5v9.0.0v9.1.0+5 more2022-06-01
CVE-2022-29098 [HIGH] CWE-521 CVE-2022-29098: Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerab
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.
nvd
CVE-2020-26193P3HIGHCVSS 7.8≥ unspecified, < 8.1.2, 8.2.2, 9.1.0+2021-02-09
CVE-2020-26193 [HIGH] CWE-20 CVE-2020-26193: Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability.
Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.
nvd
CVE-2024-22449P3HIGHCVSS 7.8≥ 9.0.0, < 9.6.1≥ 9.0.0.0, ≤ 9.4.0.0+2 more2024-02-01
CVE-2024-22449 [HIGH] CWE-306 CVE-2024-22449: Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critic
Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access.
nvd
CVE-2026-27102P3HIGHCVSS 7.8≥ 9.5.0.0, < 9.10.1.7≥ 9.11.0.0, < 9.13.0.2+1 more2026-04-08
CVE-2026-27102 [HIGH] CWE-266 CVE-2026-27102: Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, con
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
nvd
CVE-2026-21425P3HIGHCVSS 7.8fixed in 9.10.1.6≥ 9.11.0.0, < 9.13.0.0+2 more2026-03-04
CVE-2026-21425 [HIGH] CWE-266 CVE-2026-21425: Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains a
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd
CVE-2025-26480P3HIGHCVSS 7.5≥ 9.5.0.0, ≤ 9.10.0.0≥ 9.7.0.0, ≤ 9.7.1.42025-04-10
CVE-2025-26480 [HIGH] CWE-770 CVE-2025-26480: Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumpt
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2024-25968P3HIGHCVSS 7.5≥ 8.2.0, ≤ 9.3.0≥ 9.4.0, ≤ 9.4.0.17+7 more2024-05-14
CVE-2024-25968 [HIGH] CWE-327 CVE-2024-25968: Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptograph
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2024-25963P3HIGHCVSS 7.5≥ 8.2.2.0, ≤ 9.3.0≥ 9.4.0, ≤ 9.4.0.16+6 more2024-03-28
CVE-2024-25963 [HIGH] CWE-327 CVE-2024-25963: Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic alg
Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2026-25907P3HIGHCVSS 7.5v9.13.0.0≥ 9.13.0.0, < 9.13.0.1 or later2026-03-04
CVE-2026-25907 [HIGH] CWE-645 CVE-2026-25907: Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vu
Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2023-22574P3HIGHCVSS 8.1≤ 9.1.0.0 through 9.1.0.262023-02-01
CVE-2023-22574 [HIGH] CWE-532 CVE-2023-22574: Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.
nvd
CVE-2024-29170P3HIGHCVSS 8.1≥ 8.2.0, ≤ 9.8.0.0≥ 8.2.x, ≤ 9.8.0.x2024-06-04
CVE-2024-29170 [HIGH] CWE-798 CVE-2024-29170: Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnera
Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.
nvd