Dell Powerscale Onefs vulnerabilities
174 known vulnerabilities affecting dell/powerscale_onefs.
Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8
Vulnerabilities
Page 7 of 9
CVE-2022-22550P4MEDIUMCVSS 6.7v8.2.2-9.3.0.x2022-04-12
CVE-2022-22550 [MEDIUM] CWE-549 CVE-2022-22550: Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unp
Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.
nvd
CVE-2024-37132P4MEDIUMCVSS 6.7v9.8.0.0≥ 8.2.2, < 9.5.1.0+4 more2024-07-02
CVE-2024-37132 [MEDIUM] CWE-266 CVE-2024-37132: Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vul
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service and Elevation of privileges.
nvd
CVE-2022-34438P4MEDIUMCVSS 6.7≥ unspecified, < 9.4.0.x2022-10-21
CVE-2022-34438 [MEDIUM] CWE-269 CVE-2022-34438: Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.
nvd
CVE-2023-32494P4MEDIUMCVSS 6.7≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32494 [MEDIUM] CWE-274 CVE-2023-32494: Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulner
Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also.
nvd
CVE-2023-32490P4MEDIUMCVSS 6.7≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32490 [MEDIUM] CWE-269 CVE-2023-32490: Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high pr
Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.
nvd
CVE-2022-33932P4MEDIUMCVSS 5.3≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, 9.3.0.x, 9.4.0.x2022-08-22
CVE-2022-33932 [MEDIUM] CWE-419 CVE-2022-33932: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2,
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotected primary channel vulnerability. An unauthenticated network malicious attacker may potentially exploit this vulnerability, leading to a denial of filesystem services.
nvd
CVE-2021-21594P4MEDIUMCVSS 5.3v8.2.2 - 9.1.0.x2021-08-16
CVE-2021-21594 [MEDIUM] CWE-598 CVE-2021-21594: Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive qu
Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.
nvd
CVE-2026-40633P4MEDIUMCVSS 5.5≥ 9.5.0.0, < 9.10.1.8≥ 9.11.0.0, < 9.13.1.0+2 more2026-07-15
CVE-2026-40633 [MEDIUM] CWE-532 CVE-2026-40633: Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2023-25536P4MEDIUMCVSS 6.7≥ 9.4.0.0, ≤ 9.4.0.11v9.4.0.0 through 9.4.0.112023-03-02
CVE-2023-25536 [MEDIUM] CWE-200 CVE-2023-25536: Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor.
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover.
nvd
CVE-2024-39578P4MEDIUMCVSS 6.3v9.8.0.0≥ 8.2.2.0, < 9.7.1.2+1 more2024-08-31
CVE-2024-39578 [MEDIUM] CWE-61 CVE-2024-39578: Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) follo
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
nvd
CVE-2021-21565P4MEDIUMCVSS 5.3≤ 9.1.0.3≥ unspecified, ≤ 9.1.0.32021-08-03
CVE-2021-21565 [MEDIUM] CWE-400 CVE-2021-21565: Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartC
Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.
nvd
CVE-2020-26196P4MEDIUMCVSS 5.5≥ unspecified, < 8.1.2, 8.2.1, 8.2.2, 9.0.02021-02-09
CVE-2020-26196 [MEDIUM] CWE-732 CVE-2020-26196: Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation iss
Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentially exploit this vulnerability resulting in the ability to write data outside of the intended file system location.
nvd
CVE-2021-36280P4MEDIUMCVSS 5.5v8.2.x - 9.2.x2021-08-16
CVE-2021-36280 [MEDIUM] CWE-732 CVE-2021-36280: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for crit
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster.
nvd
CVE-2022-31238P4MEDIUMCVSS 5.5≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.1.1.x, 9.2.0.x, 9.2.1.x, 9.3.0.x2022-08-22
CVE-2022-31238 [MEDIUM] CWE-200 CVE-2022-31238: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2,
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive information vulnerability. A CLI user may potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2024-25959P4MEDIUMCVSS 5.5≥ 9.4.0, < 9.4.0.17≥ 9.5.0.0, < 9.5.0.8+5 more2024-03-28
CVE-2024-25959 [MEDIUM] CWE-532 CVE-2024-25959: Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive informatio
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.
nvd
CVE-2025-30477P4MEDIUMCVSS 4.9fixed in 9.11.0.0≥ N/A, < 9.11.0.02025-07-21
CVE-2025-30477 [MEDIUM] CWE-327 CVE-2025-30477: Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic
Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2024-25952P4MEDIUMCVSS 6.0≥ 8.2.2.0, ≤ 9.3.0≥ 9.4.0, ≤ 9.4.0.16+7 more2024-03-28
CVE-2024-25952 [MEDIUM] CWE-61 CVE-2024-25952: Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) foll
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
nvd
CVE-2024-25953P4MEDIUMCVSS 6.0≥ 9.4.0, ≤ 9.4.0.16≥ 9.5.0.0, < 9.5.0.8+5 more2024-03-28
CVE-2024-25953 [MEDIUM] CWE-61 CVE-2024-25953: Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) foll
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
nvd
CVE-2026-22280P4MEDIUMCVSS 5.5≥ 9.5.0.0, < 9.5.1.6≥ 9.6.0.0, < 9.7.1.11+6 more2026-01-22
CVE-2026-22280 [MEDIUM] CWE-732 CVE-2026-22280: Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains an incorrect permission assignment for critical resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability
nvd
CVE-2022-45098P4MEDIUMCVSS 5.5≥ 9.0.0.x, ≤ 0.4.0.x2023-02-01
CVE-2022-45098 [MEDIUM] CWE-532 CVE-2022-45098: Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulner
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.
nvd