Dell Powerscale Onefs vulnerabilities
174 known vulnerabilities affecting dell/powerscale_onefs.
Total CVEs
174
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH62MEDIUM89LOW8
Vulnerabilities
Page 9 of 9
CVE-2021-21562P4MEDIUMCVSS 4.4v8.1.2, 8.1.3, 9.1.0.x, 9.0.0.x2021-08-03
CVE-2021-21562 [MEDIUM] CWE-426 CVE-2021-21562: Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application’s direct control.
nvd
CVE-2022-34445P4MEDIUMCVSS 4.4v8.2.0v8.2.1+8 more2023-02-11
CVE-2022-34445 [MEDIUM] CWE-261 CVE-2022-34445: Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malic
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2022-22563P4MEDIUMCVSS 4.4≥ unspecified, < 9.3.0.x2022-04-08
CVE-2022-22563 [MEDIUM] CWE-223 CVE-2022-22563: Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A
Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.
nvd
CVE-2024-25965P4MEDIUMCVSS 4.4≥ 8.2.0, ≤ 9.3.0≥ 9.4.0, ≤ 9.4.0.17+7 more2024-05-14
CVE-2024-25965 [MEDIUM] CWE-73 CVE-2024-25965: Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or pa
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2025-43935P4MEDIUMCVSS 4.4fixed in 9.5.1.5≥ 9.6.0.0, < 9.7.1.10+6 more2026-04-16
CVE-2025-43935 [MEDIUM] CWE-404 CVE-2025-43935: Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2025-43883P4MEDIUMCVSS 4.1fixed in 9.5.1.5≥ 9.6.0.0, < 9.7.1.10+6 more2026-04-16
CVE-2025-43883 [MEDIUM] CWE-754 CVE-2025-43883: Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or excepti
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.
nvd
CVE-2022-24413P4LOWCVSS 3.6v8.2.2-9.3.x2022-04-12
CVE-2022-24413 [LOW] CWE-367 CVE-2022-24413: Dell PowerScale OneFS, versions 8.2.2-9.3.x, contain a time-of-check-to-time-of-use vulnerability. A
Dell PowerScale OneFS, versions 8.2.2-9.3.x, contain a time-of-check-to-time-of-use vulnerability. A local user with access to the filesystem could potentially exploit this vulnerability, leading to data loss.
nvd
CVE-2021-36282P4LOWCVSS 3.3v8.2.x - 9.1.0.x2021-08-16
CVE-2021-36282 [LOW] CWE-908 CVE-2021-36282: Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerabi
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can potentially allow an authenticated user with ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to gain access up to 24 bytes of data within the /ifs kernel stack under certain conditions.
nvd
CVE-2025-26479P4LOWCVSS 3.1≥ 9.4.0, < 9.10.1.1≥ 9.4.0.0, ≤ 9.10.0.1+2 more2025-04-10
CVE-2025-26479 [LOW] CWE-787 CVE-2025-26479: Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerabil
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.
nvd
CVE-2022-22565P4LOWCVSS 3.8v9.0.0-9.3.02022-04-12
CVE-2022-22565 [LOW] CWE-612 CVE-2022-22565: Dell PowerScale OneFS, versions 9.0.0-9.3.0, contain an improper authorization of index containing s
Dell PowerScale OneFS, versions 9.0.0-9.3.0, contain an improper authorization of index containing sensitive information. An authenticated and privileged user could potentially exploit this vulnerability, leading to disclosure or modification of sensitive data.
nvd
CVE-2026-32803P4LOWCVSS 3.3≥ 9.5.0.0, < 9.5.1.7≥ 9.6.0.0, < 9.7.1.14+6 more2026-05-08
CVE-2026-32803 [LOW] CWE-778 CVE-2026-32803: Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.
Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
nvd
CVE-2022-31237P4LOWCVSS 3.3≥ unspecified, < 9.2.0.x, 9.2.1.x, 9.3.0.x2022-08-22
CVE-2022-31237 [LOW] CWE-281 CVE-2022-31237: Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper p
Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to limited information disclosure.
nvd
CVE-2025-23378P4LOWCVSS 3.3≥ 9.4.0, ≤ 9.10.0.0≥ 9.4.0.0, ≤ 9.10.0.0+2 more2025-04-10
CVE-2025-23378 [LOW] CWE-548 CVE-2025-23378: Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information throug
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2024-24901P4LOWCVSS 2.3≥ 8.2.0, < 9.2.1.25≥ 9.3.0.0, < 9.4.0.17+6 more2024-03-04
CVE-2024-24901 [LOW] CWE-778 CVE-2024-24901: Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local m
Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.
nvd
← Previous9 / 9