VYPR

Powerscale Onefs

by Dell

CVEs (180)

  • CVE-2023-25536MedMar 2, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover.

  • CVE-2022-34454MedFeb 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters.

  • CVE-2022-45095MedFeb 1, 2023
    risk 0.44cvss 6.7epss 0.01

    Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of…

  • CVE-2022-34438MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

  • CVE-2022-34437MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This impacts compliance mode clusters.

  • CVE-2022-31239MedOct 21, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.

  • CVE-2022-22550MedApr 12, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.

  • CVE-2025-43937MedApr 16, 2026
    risk 0.43cvss 6.6epss 0.00

    Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The…

  • CVE-2026-27102MedApr 8, 2026
    risk 0.43cvss 6.6epss 0.00

    Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of…

  • CVE-2024-22449MedFeb 1, 2024
    risk 0.43cvss 6.6epss 0.00

    Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access.

  • CVE-2025-22471MedApr 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2024-47239MedJan 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2024-49602MedDec 9, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2024-25970MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.

  • CVE-2023-43076MedNov 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition.

  • CVE-2023-25942MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service.

  • CVE-2022-46679MedFeb 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2021-36305MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An authenticated user of SMB on a cluster with CA could potentially exploit this vulnerability, leading to a denial of service over SMB.

  • CVE-2021-21563MedAug 3, 2021
    risk 0.42cvss 6.5epss 0.01

    Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.

  • CVE-2024-39578MedAug 31, 2024
    risk 0.41cvss 6.3epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.

Page 5 of 9