Dell Powerscale Onefs vulnerabilities
174 known vulnerabilities affecting dell/powerscale_onefs.
Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8
Vulnerabilities
Page 5 of 9
CVE-2022-45095P4MEDIUMCVSS 6.7≥ 8.2.x, ≤ 9.4.x2023-02-01
CVE-2022-45095 [MEDIUM] CWE-77 CVE-2022-45095: Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated use
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and data deletion.
nvd
CVE-2021-21599P4MEDIUMCVSS 6.7v8.2.x - 9.2.1.x2021-08-16
CVE-2021-21599 [MEDIUM] CWE-78 CVE-2021-21599: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. Th
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgra
nvd
CVE-2021-21526P4MEDIUMCVSS 6.7≥ 8.1.0, ≤ 9.1.0≥ unspecified, < 8.1.0-9.1.02021-04-20
CVE-2021-21526 [MEDIUM] CWE-78 CVE-2021-21526: Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode tha
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary commands as root.
nvd
CVE-2026-21422P4MEDIUMCVSS 6.7≥ 9.10.0.0, < 9.10.1.6≥ 9.11.0.0, < 9.13.0.0+2 more2026-03-04
CVE-2026-21422 [MEDIUM] CWE-15 CVE-2026-21422: Dell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or
Dell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setting vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to protection mechanism bypass.
nvd
CVE-2022-23159P4MEDIUMCVSS 6.5v8.2.2 - 9.3.0.x2022-04-12
CVE-2022-23159 [MEDIUM] CWE-401 CVE-2022-23159: Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contain a missing release of memory after effective lifetime
Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contain a missing release of memory after effective lifetime vulnerability. An authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE and ISI_PRIV_AUTH_PROVIDERS privileges could exploit this vulnerability, leading to a Denial-Of-Service. This can also impact a cluster in Compliance mode. Del
nvd
CVE-2024-42426P4MEDIUMCVSS 6.5v9.8.0.0≥ 9.5.0.0, < 9.7.1.3+1 more2024-12-09
CVE-2024-42426 [MEDIUM] CWE-400 CVE-2024-42426: Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption
Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2024-47239P4MEDIUMCVSS 6.5≥ 9.5.0.0, < 9.5.1.2≥ 9.8.0.0, < 9.9.0.1+6 more2025-01-08
CVE-2024-47239 [MEDIUM] CWE-400 CVE-2024-47239: Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption
Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2025-22471P4MEDIUMCVSS 6.5≥ 9.4.0, < 9.10.1.1≥ 9.4.0.0, ≤ 9.10.0.1+2 more2025-04-10
CVE-2025-22471 [MEDIUM] CWE-190 CVE-2025-22471: Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2024-49602P4MEDIUMCVSS 6.5v9.8.0.0≥ 8.2.2, < 9.7.1.3+5 more2024-12-09
CVE-2024-49602 [MEDIUM] CWE-765 CVE-2024-49602: Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulner
Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2023-32492P4HIGHCVSS 7.1≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32492 [HIGH] CWE-276 CVE-2023-32492: Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privil
Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.
nvd
CVE-2026-21424P4MEDIUMCVSS 6.7fixed in 9.10.1.6≥ 9.11.0.0, < 9.13.0.0+2 more2026-03-04
CVE-2026-21424 [MEDIUM] CWE-250 CVE-2026-21424: Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains a
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd
CVE-2026-21421P4MEDIUMCVSS 6.7fixed in 9.10.1.6≥ 9.11.0.0, < 9.13.0.0+2 more2026-03-04
CVE-2026-21421 [MEDIUM] CWE-250 CVE-2026-21421: Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains a
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
nvd
CVE-2026-49501P4MEDIUMCVSS 6.7≥ 9.5.0.0, < 9.10.1.8≥ 9.11.0.0, < 9.13.1.0+2 more2026-07-15
CVE-2026-49501 [MEDIUM] CWE-269 CVE-2026-49501: Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 cont
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd
CVE-2023-25942P4MEDIUMCVSS 6.5v9.2.1.0 through 9.2.1.21 9.4.0.0 through 9.4.0.12 9.5.0.0v9.1.0.0 through 9.1.0.28+1 more2023-04-04
CVE-2023-25942 [MEDIUM] CWE-664 CVE-2023-25942: Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerabili
Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service.
nvd
CVE-2022-45096P4MEDIUMCVSS 6.5≥ 8.2.0, ≤ 9.3.02023-02-01
CVE-2022-45096 [MEDIUM] CWE-355 CVE-2022-45096: Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenti
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information.
nvd
CVE-2020-26195P4MEDIUMCVSS 5.3≥ unspecified, < 8.1.2, 8.2.2, 9.0+2021-02-09
CVE-2020-26195 [MEDIUM] CWE-280 CVE-2020-26195: Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto
Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issue to slow down the system.
nvd
CVE-2025-26330P4HIGHCVSS 7.0≥ 9.4.0, ≤ 9.10.1.1≥ 9.4.0.0, ≤ 9.10.0.1+1 more2025-04-10
CVE-2025-26330 [HIGH] CWE-863 CVE-2025-26330: Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulner
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
nvd
CVE-2022-34437P4MEDIUMCVSS 6.7≥ unspecified, < 9.4.0.x2022-10-21
CVE-2022-34437 [MEDIUM] CWE-78 CVE-2022-34437: Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privil
Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This impacts compliance mode clusters.
nvd
CVE-2021-36305P4MEDIUMCVSS 6.5v8.2.0, 8.2.1, 9.0.0.x, 9.2.0.x, 9.1.1.x, 8.2.2, 9.1.0.x , 9.2.1.x2021-11-12
CVE-2021-36305 [MEDIUM] CWE-662 CVE-2021-36305: Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in
Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An authenticated user of SMB on a cluster with CA could potentially exploit this vulnerability, leading to a denial of service over SMB.
nvd
CVE-2021-21595P4MEDIUMCVSS 6.7v8.2.x - 9.1.1.x2021-08-16
CVE-2021-21595 [MEDIUM] CWE-77 CVE-2021-21595: Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special ele
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunit
nvd