VYPR

Powerscale Onefs

by Dell

CVEs (180)

  • CVE-2023-44295MedDec 5, 2023
    risk 0.41cvss 6.3epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.

  • CVE-2023-32491MedAug 16, 2023
    risk 0.41cvss 6.3epss 0.00

    Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2022-45097MedFeb 1, 2023
    risk 0.41cvss 6.3epss 0.00

    Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure.

  • CVE-2022-24428MedApr 8, 2022
    risk 0.41cvss 6.3epss 0.01

    Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and…

  • CVE-2020-26180MedJul 28, 2021
    risk 0.41cvss 6.3epss 0.01

    Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account. A remote malicious user with low privileges may gain access to data stored on the /ifs directory through most…

  • CVE-2024-25969MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2024-25965MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2022-45098MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2024-25953MedMar 28, 2024
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.

  • CVE-2024-25952MedMar 28, 2024
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.

  • CVE-2024-25961MedMar 28, 2024
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-25540MedFeb 28, 2023
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service.

  • CVE-2022-34445MedFeb 11, 2023
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2021-21599MedAug 16, 2021
    risk 0.39cvss 6.0epss 0.00

    Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartlock WORM compliance mode…

  • CVE-2021-21595MedAug 16, 2021
    risk 0.39cvss 6.0epss 0.00

    Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical…

  • CVE-2021-21550MedMay 6, 2021
    risk 0.39cvss 6.0epss 0.00

    Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability can allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.

  • CVE-2021-21527MedMay 6, 2021
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.

  • CVE-2021-21526MedApr 20, 2021
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary commands as root.

  • CVE-2025-43723MedNov 10, 2025
    risk 0.38cvss 5.9epss 0.00

    Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2024-32852MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit this vulnerability, leading to data leaks.

Page 6 of 9