cbcvebase.

Dell Powerscale Onefs vulnerabilities

174 known vulnerabilities affecting dell/powerscale_onefs.

Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8

Vulnerabilities

Page 4 of 9
CVE-2022-45099P3HIGHCVSS 7.8≥ 8.2.x, ≤ 9.4.x2023-02-01
CVE-2022-45099 [HIGH] CWE-261 CVE-2022-45099: Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicio Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise
nvd
CVE-2023-32487P3HIGHCVSS 7.8≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32487 [HIGH] CWE-269 CVE-2023-32487: Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low pri Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosure.
nvd
CVE-2023-32486P3HIGHCVSS 7.8≥ 9.5.0.0, ≤ 9.5.0.3vVersion 9.5.0.0 through 9.5.0.32023-08-16
CVE-2023-32486 [HIGH] CWE-250 CVE-2023-32486: Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege l Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2022-46679P3HIGHCVSS 7.5≥ 8.2.x;9.0.0.x, ≤ 9.4.0.x2023-02-01
CVE-2022-46679 [HIGH] CWE-410 CVE-2022-46679: Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2022-22559P3HIGHCVSS 7.5v9.3.0.x2022-04-12
CVE-2022-22559 [HIGH] CWE-327 CVE-2022-22559: Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm. A Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm. An unprivileged network attacker could exploit this vulnerability, leading to the potential for information disclosure.
nvd
CVE-2022-24412P3HIGHCVSS 7.5v8.2.x - 9.3.0.x2022-04-12
CVE-2022-24412 [HIGH] CWE-229 CVE-2022-24412: Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An un Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.
nvd
CVE-2021-36279P3HIGHCVSS 7.8v8.2.x - 9.2.x2021-08-16
CVE-2021-36279 [HIGH] CWE-732 CVE-2021-36279: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for crit Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster.
nvd
CVE-2023-22572P3HIGHCVSS 7.8≤ 9.1.0.0 through 9.1.0.262023-02-01
CVE-2023-22572 [HIGH] CWE-532 CVE-2023-22572: Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file v Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover.
nvd
CVE-2023-32495P3HIGHCVSS 7.8≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32495 [HIGH] CWE-200 CVE-2023-32495: Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2024-25970P3MEDIUMCVSS 6.5≥ 8.2.0, ≤ 9.3.0≥ 9.4.0, < 9.4.0.18+6 more2024-05-14
CVE-2024-25970 [MEDIUM] CWE-20 CVE-2024-25970: Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerabi Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.
nvd
CVE-2021-21503P3HIGHCVSS 7.8≥ unspecified, < 8.1.2, 8.2.2,9.1.0.x,EMPIRE (9.2.0), GOTHAM2021-03-08
CVE-2021-21503 [HIGH] CWE-78 CVE-2021-21503: PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. T PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially exploit this vulnerability, leading to potential privileges escalation.
nvd
CVE-2021-21567P3HIGHCVSS 7.8v9.0.0.0v9.1.0.0+1 more2021-08-10
CVE-2021-21567 [HIGH] CWE-732 CVE-2021-21567: Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege.
nvd
CVE-2022-23161P3HIGHCVSS 7.5v8.2.x - 9.3.0.x2022-04-12
CVE-2022-23161 [HIGH] CWE-755 CVE-2022-23161: Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartCon Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerability, leading to denial-of-service.
nvd
CVE-2023-25941P3HIGHCVSS 7.8v9.2.1.0 through 9.2.1.21 9.4.0.0 through 9.4.0.12v9.1.0.0 through 9.1.0.28+1 more2023-04-04
CVE-2023-25941 [HIGH] CWE-276 CVE-2023-25941: Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability breaks the compliance mode guarantee.
nvd
CVE-2024-25960P3HIGHCVSS 7.8≥ 8.2.2.0, ≤ 9.3.0≥ 9.4.0, < 9.4.0.17+6 more2024-03-28
CVE-2024-25960 [HIGH] CWE-319 CVE-2024-25960: Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitiv Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2024-49603P3MEDIUMCVSS 6.5≥ 9.8.0.0, < 9.9.0.1≥ 8.2.2, < 9.7.1.3+2 more2024-12-09
CVE-2024-49603 [MEDIUM] CWE-687 CVE-2024-49603: Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulne Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2022-32480P3MEDIUMCVSS 6.5≥ unspecified, < 9.1.0.x, 9.2.0.x,, 9.2.1.x, 9.3.0.x2022-08-22
CVE-2022-32480 [MEDIUM] CWE-1188 CVE-2022-32480: Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2021-21592P4MEDIUMCVSS 6.5v8.2.x - 9.2.x2021-08-16
CVE-2021-21592 [MEDIUM] CWE-755 CVE-2021-21592: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remot Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.
nvd
CVE-2023-43087P4MEDIUMCVSS 6.5≥ 8.2.0, ≤ 8.2.2≥ 9.2.1, < 9.2.1.24+3 more2023-11-02
CVE-2023-43087 [MEDIUM] CWE-280 CVE-2023-43087: Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissi Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.
nvd
CVE-2023-32491P4MEDIUMCVSS 6.5≥ 9.5.0.0, ≤ 9.5.0.3vVersion 9.5.0.0 through 9.5.0.32023-08-16
CVE-2023-32491 [MEDIUM] CWE-532 CVE-2023-32491: Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnera Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.
nvd
Dell Powerscale Onefs vulnerabilities | cvebase