cbcvebase.

Dell Powerscale Onefs vulnerabilities

174 known vulnerabilities affecting dell/powerscale_onefs.

Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8

Vulnerabilities

Page 3 of 9
CVE-2024-25966P3HIGHCVSS 7.5≥ 8.2.0, ≤ 9.3.0≥ 9.4.0, < 9.4.0.18+7 more2024-05-14
CVE-2024-25966 [HIGH] CWE-241 CVE-2024-25966: Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected dat Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2025-32753P3HIGHCVSS 7.8≥ 9.5.0.0, ≤ 9.10.0.12025-06-20
CVE-2025-32753 [HIGH] CWE-89 CVE-2025-32753: Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of spe Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, information disclosure, and information tampering.
nvd
CVE-2022-34369P3HIGHCVSS 7.5≥ unspecified, < 9.0.0.x, 9.1.0.x, 9.1.1.x, 9.2.0.x, 9.2.1.x, 9.3.0.x. 9.4.0.x, 9.5.0.x2022-09-02
CVE-2022-34369 [HIGH] CWE-532 CVE-2022-34369: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this sensitive data.
nvd
CVE-2022-34444P3HIGHCVSS 7.5v9.2.0v9.2.1+3 more2023-02-11
CVE-2022-34444 [HIGH] CWE-327 CVE-2022-34444: Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A rem Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak.
nvd
CVE-2024-32852P3HIGHCVSS 7.5≥ 8.2.0, < 9.5.1.0≥ 9.6.0, < 9.7.1.0+1 more2024-07-02
CVE-2024-32852 [HIGH] CWE-327 CVE-2024-32852: Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographi Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit this vulnerability, leading to data leaks.
nvd
CVE-2020-26191P3HIGHCVSS 7.8≥ unspecified, < 8.1.2, 8.2.2, 9.1.0+2021-02-09
CVE-2020-26191 [HIGH] CWE-269 CVE-2020-26191: Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A use Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the PermissionRepair job to grant themselves the highest level of RBAC privileges thus being able to read arbitrary data, tamper with system software or deny service to users.
nvd
CVE-2020-26192P3HIGHCVSS 7.8≥ unspecified, < 8.2.2, 9.1+2021-02-09
CVE-2020-26192 [HIGH] CWE-306 CVE-2020-26192: Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH may potentially exploit this vulnerability to read arbitrary data, tamper with system software or deny service to users. Note: no non-admin users or roles have these privileges by defa
nvd
CVE-2024-32853P3HIGHCVSS 7.8≥ 8.2.2, < 9.4.0.18≥ 9.5.0.0, < 9.5.1.0+3 more2024-07-02
CVE-2024-32853 [HIGH] CWE-250 CVE-2024-32853: Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privile Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2022-22562P3HIGHCVSS 7.5v8.2.0-9.2.1.x,2022-04-12
CVE-2022-22562 [HIGH] CWE-229 CVE-2022-22562: Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker could potentially exploit this denial-of-service vulnerability.
nvd
CVE-2022-34439P3HIGHCVSS 7.5≥ unspecified, < 9.4.0.x2022-10-21
CVE-2022-34439 [HIGH] CWE-770 CVE-2022-34439: Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Th Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service and performance issue on that node.
nvd
CVE-2024-25964P3HIGHCVSS 7.5≥ 9.5.0.0, < 9.5.0.7≥ 9.6.1, < 9.7.0.1+2 more2024-03-25
CVE-2024-25964 [HIGH] CWE-385 CVE-2024-25964: Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remot Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2023-23689P3HIGHCVSS 7.5v9.5.0.x, 9.4.0.x, 9.3.0.x, 9.2.1.x, 9.2.0.x, 9.1.0.x, 9.0.0.x2023-02-28
CVE-2023-23689 [HIGH] CWE-400 CVE-2023-23689: Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware manageme Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains an uncontrolled resource consumption vulnerability. This may allow an unauthenticated network host to impair built-in hardware management functionality and trigger OneFS data protection mechanism causing a denial of service.
nvd
CVE-2024-25954P3HIGHCVSS 7.5≥ 9.5.0.0, < 9.5.0.8≥ 9.6.1, < 9.7.0.2+3 more2024-03-28
CVE-2024-25954 [HIGH] CWE-613 CVE-2024-25954: Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2020-26181P3HIGHCVSS 7.8≥ unspecified, < 8.1.2, 8.2.2, 9.0+2021-01-05
CVE-2020-26181 [HIGH] CWE-269 CVE-2020-26181: Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a p Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV HARDENING privileges.
nvd
CVE-2020-26194P3HIGHCVSS 7.8≥ unspecified, < 8.1.2, 8.2.22021-02-09
CVE-2020-26194 [HIGH] CWE-732 CVE-2020-26194: Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This may allow a non-admin user with either ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to exploit the vulnerability, leading to compromised cryptographic operations. Note: no non-admin users or roles have the
nvd
CVE-2023-44288P3HIGHCVSS 7.5≥ 8.2.2, ≤ 9.6.1vVersion 8.2.2.x through 9.6.0.x2023-12-05
CVE-2023-44288 [HIGH] CWE-664 CVE-2023-44288: Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2025-26481P3HIGHCVSS 7.5≥ 9.4.0, ≤ 9.9.0.0≥ 9.4.0.0, ≤ 9.9.0.02025-05-15
CVE-2025-26481 [HIGH] CWE-400 CVE-2025-26481: Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumpti Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2022-24411P3HIGHCVSS 7.8v8.2.2 - 9.3.0.x2022-04-12
CVE-2022-24411 [HIGH] CWE-378 CVE-2022-24411: Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attac Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to circumvent PowerScale Compliance Mode guarantees.
nvd
CVE-2023-25940P3HIGHCVSS 7.8v9.5.0.02023-04-04
CVE-2023-25940 [HIGH] CWE-59 CVE-2023-25940: Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerab Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.
nvd
CVE-2021-21528P3HIGHCVSS 7.5v9.1.0, 9.2.0.x, 9.2.1.x2021-11-12
CVE-2021-21528 [HIGH] CWE-548 CVE-2021-21528: Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information throug Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing vulnerability. This vulnerability is triggered when upgrading from a previous versions.
nvd
Dell Powerscale Onefs vulnerabilities | cvebase