Dell Powerscale Onefs vulnerabilities
174 known vulnerabilities affecting dell/powerscale_onefs.
Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8
Vulnerabilities
Page 4 of 9
CVE-2022-45099P3HIGHCVSS 7.8≥ 8.2.x, ≤ 9.4.x2023-02-01
CVE-2022-45099 [HIGH] CWE-261 CVE-2022-45099: Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicio
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise
nvd
CVE-2023-32487P3HIGHCVSS 7.8≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32487 [HIGH] CWE-269 CVE-2023-32487: Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low pri
Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosure.
nvd
CVE-2023-32486P3HIGHCVSS 7.8≥ 9.5.0.0, ≤ 9.5.0.3vVersion 9.5.0.0 through 9.5.0.32023-08-16
CVE-2023-32486 [HIGH] CWE-250 CVE-2023-32486: Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege l
Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2022-46679P3HIGHCVSS 7.5≥ 8.2.x;9.0.0.x, ≤ 9.4.0.x2023-02-01
CVE-2022-46679 [HIGH] CWE-410 CVE-2022-46679: Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability
Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2022-22559P3HIGHCVSS 7.5v9.3.0.x2022-04-12
CVE-2022-22559 [HIGH] CWE-327 CVE-2022-22559: Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm. A
Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm. An unprivileged network attacker could exploit this vulnerability, leading to the potential for information disclosure.
nvd
CVE-2022-24412P3HIGHCVSS 7.5v8.2.x - 9.3.0.x2022-04-12
CVE-2022-24412 [HIGH] CWE-229 CVE-2022-24412: Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An un
Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.
nvd
CVE-2021-36279P3HIGHCVSS 7.8v8.2.x - 9.2.x2021-08-16
CVE-2021-36279 [HIGH] CWE-732 CVE-2021-36279: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for crit
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster.
nvd
CVE-2023-22572P3HIGHCVSS 7.8≤ 9.1.0.0 through 9.1.0.262023-02-01
CVE-2023-22572 [HIGH] CWE-532 CVE-2023-22572: Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file v
Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover.
nvd
CVE-2023-32495P3HIGHCVSS 7.8≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32495 [HIGH] CWE-200 CVE-2023-32495: Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized
Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2024-25970P3MEDIUMCVSS 6.5≥ 8.2.0, ≤ 9.3.0≥ 9.4.0, < 9.4.0.18+6 more2024-05-14
CVE-2024-25970 [MEDIUM] CWE-20 CVE-2024-25970: Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerabi
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.
nvd
CVE-2021-21503P3HIGHCVSS 7.8≥ unspecified, < 8.1.2, 8.2.2,9.1.0.x,EMPIRE (9.2.0), GOTHAM2021-03-08
CVE-2021-21503 [HIGH] CWE-78 CVE-2021-21503: PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. T
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially exploit this vulnerability, leading to potential privileges escalation.
nvd
CVE-2021-21567P3HIGHCVSS 7.8v9.0.0.0v9.1.0.0+1 more2021-08-10
CVE-2021-21567 [HIGH] CWE-732 CVE-2021-21567: Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow
Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE to elevate privilege.
nvd
CVE-2022-23161P3HIGHCVSS 7.5v8.2.x - 9.3.0.x2022-04-12
CVE-2022-23161 [HIGH] CWE-755 CVE-2022-23161: Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartCon
Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerability, leading to denial-of-service.
nvd
CVE-2023-25941P3HIGHCVSS 7.8v9.2.1.0 through 9.2.1.21 9.4.0.0 through 9.4.0.12v9.1.0.0 through 9.1.0.28+1 more2023-04-04
CVE-2023-25941 [HIGH] CWE-276 CVE-2023-25941: Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability breaks the compliance mode guarantee.
nvd
CVE-2024-25960P3HIGHCVSS 7.8≥ 8.2.2.0, ≤ 9.3.0≥ 9.4.0, < 9.4.0.17+6 more2024-03-28
CVE-2024-25960 [HIGH] CWE-319 CVE-2024-25960: Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitiv
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.
nvd
CVE-2024-49603P3MEDIUMCVSS 6.5≥ 9.8.0.0, < 9.9.0.1≥ 8.2.2, < 9.7.1.3+2 more2024-12-09
CVE-2024-49603 [MEDIUM] CWE-687 CVE-2024-49603: Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulne
Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2022-32480P3MEDIUMCVSS 6.5≥ unspecified, < 9.1.0.x, 9.2.0.x,, 9.2.1.x, 9.3.0.x2022-08-22
CVE-2022-32480 [MEDIUM] CWE-1188 CVE-2022-32480: Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2,
Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2021-21592P4MEDIUMCVSS 6.5v8.2.x - 9.2.x2021-08-16
CVE-2021-21592 [MEDIUM] CWE-755 CVE-2021-21592: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remot
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.
nvd
CVE-2023-43087P4MEDIUMCVSS 6.5≥ 8.2.0, ≤ 8.2.2≥ 9.2.1, < 9.2.1.24+3 more2023-11-02
CVE-2023-43087 [MEDIUM] CWE-280 CVE-2023-43087: Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissi
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.
nvd
CVE-2023-32491P4MEDIUMCVSS 6.5≥ 9.5.0.0, ≤ 9.5.0.3vVersion 9.5.0.0 through 9.5.0.32023-08-16
CVE-2023-32491 [MEDIUM] CWE-532 CVE-2023-32491: Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnera
Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.
nvd