Dell Powerscale Onefs vulnerabilities
174 known vulnerabilities affecting dell/powerscale_onefs.
Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8
Vulnerabilities
Page 8 of 9
CVE-2021-36278P4MEDIUMCVSS 5.5v8.2.x, 9.1.0.x2021-08-16
CVE-2021-36278 [MEDIUM] CWE-532 CVE-2021-36278: Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information expos
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious user with ISI_PRIV_LOGIN_SSH, ISI_PRIV_LOGIN_CONSOLE, or ISI_PRIV_SYS_SUPPORT privileges may exploit this vulnerability to access sensitive information. If any third-party consumes those logs, the same
nvd
CVE-2021-21561P4MEDIUMCVSS 5.5≥ unspecified, < 8.1.0, 8.1.1, 8.1.2, 8.2.x, 9.1.0.x2021-11-23
CVE-2021-21561 [MEDIUM] CWE-532 CVE-2021-21561: Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This wo
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.
nvd
CVE-2024-25969P4MEDIUMCVSS 5.5≥ 8.2.0, ≤ 9.3.0≥ 9.4.0, < 9.4.0.18+6 more2024-05-14
CVE-2024-25969 [MEDIUM] CWE-770 CVE-2024-25969: Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without lim
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2022-22560P4MEDIUMCVSS 5.5v8.1.x-9.2.1.x2022-04-12
CVE-2022-22560 [MEDIUM] CWE-798 CVE-2022-22560: Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user wit
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch offline.
nvd
CVE-2023-22573P4MEDIUMCVSS 5.5≤ 9.1.0.0 through 9.1.0.262023-02-01
CVE-2023-22573 [MEDIUM] CWE-532 CVE-2023-22573: Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vu
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.
nvd
CVE-2022-31229P4MEDIUMCVSS 4.9≥ 8.2.0, ≤ 9.3.0.0≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.1.1.x, 9.2.0.x, 9.2.1.x, 9.3.0.x2022-06-28
CVE-2022-31229 [MEDIUM] CWE-209 CVE-2022-31229: Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. A
Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator could potentially exploit this vulnerability, leading to disclosure of sensitive information. This sensitive information can be used to access sensitive resources.
nvd
CVE-2022-34378P4MEDIUMCVSS 5.5≥ unspecified, < 8.2.x, 9.0.0.x, 9.1.0.x, 9.1.1.x, 9.2.0.x, 9.2.1.x, 9.3.0.x. 9.4.0.x, 9.5.0.x2022-09-02
CVE-2022-34378 [MEDIUM] CWE-23 CVE-2022-34378: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3,
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2025-30102P4MEDIUMCVSS 5.5≥ 9.4.0.0, < 9.10.1.2≥ 9.4.0.0, ≤ 9.10.1.02025-05-08
CVE-2025-30102 [MEDIUM] CWE-787 CVE-2025-30102: Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerabil
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2024-22430P4MEDIUMCVSS 5.5≥ 8.2.0, < 9.6.1≥ 8.2.0, ≤ 8.2.2+3 more2024-02-01
CVE-2024-22430 [MEDIUM] CWE-276 CVE-2024-22430: Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vuln
Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2024-47475P4MEDIUMCVSS 5.5≥ 9.8.0.0, ≤ 9.8.0.2≥ 8.2.2, < 9.4.0.20+3 more2025-01-06
CVE-2024-47475 [MEDIUM] CWE-732 CVE-2024-47475: Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critic
Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2026-22281P4MEDIUMCVSS 4.8≥ 9.5.0.0, < 9.5.1.6≥ 9.6.0.0, < 9.7.1.11+6 more2026-01-22
CVE-2026-22281 [MEDIUM] CWE-367 CVE-2026-22281: Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnera
nvd
CVE-2021-21568P4MEDIUMCVSS 4.3v8.2.x - 9.2.x2021-08-16
CVE-2021-21568 [MEDIUM] CVE-2021-21568: Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An a
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An authenticated user with ISI_PRIV_LOGIN_PAPI could make un-audited and un-trackable configuration changes to settings that their roles have privileges to change.
nvd
CVE-2022-33934P4MEDIUMCVSS 4.8≥ 8.2.x, ≤ 9.4.x2023-02-10
CVE-2022-33934 [MEDIUM] CWE-79 CVE-2022-33934: Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vu
Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected fields.
nvd
CVE-2022-23160P4MEDIUMCVSS 4.3v8.2.0-9.3.02022-04-12
CVE-2022-23160 [MEDIUM] CWE-274 CVE-2022-23160: Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissio
Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious user could potentially exploit this vulnerability, leading to gaining write permissions on read-only files.
nvd
CVE-2025-43724P4MEDIUMCVSS 4.4≥ 9.8.0.0, < 9.10.1.3≥ 9.5.0.0, < 9.5.1.5+3 more2025-10-08
CVE-2025-43724 [MEDIUM] CWE-639 CVE-2025-43724: Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-con
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares.
nvd
CVE-2022-26855P4MEDIUMCVSS 5.5≥ unspecified, < 8.2.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, 9.3.0.x2022-04-08
CVE-2022-26855 [MEDIUM] CWE-276 CVE-2022-26855: Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerabili
Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability, leading to a denial of service.
nvd
CVE-2023-32488P4MEDIUMCVSS 4.3≥ 9.2.1.0, ≤ 9.2.1.22≥ 9.4.0.0, ≤ 9.4.0.13+2 more2023-08-16
CVE-2023-32488 [MEDIUM] CWE-1230 CVE-2023-32488: Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A lo
Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2022-23163P4MEDIUMCVSS 5.5v8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x2022-04-12
CVE-2022-23163 [MEDIUM] CWE-379 CVE-2022-23163: Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerabilit
Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious user could potentially exploit this vulnerability, leading to denial of service/data unavailability.
nvd
CVE-2022-31239P4MEDIUMCVSS 4.4≥ unspecified, < 9.3.0.x2022-10-21
CVE-2022-31239 [MEDIUM] CWE-532 CVE-2022-31239: Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain s
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.
nvd
CVE-2026-24511P4MEDIUMCVSS 4.4≥ 9.5.0.0, < 9.10.1.7≥ 9.11.0.0, < 9.13.0.1+1 more2026-04-08
CVE-2026-24511 [MEDIUM] CWE-209 CVE-2026-24511: Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, con
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
nvd