Show filters
143 Total Results
Displaying 51-60 of 143
Sort by:
Attacker Value
Unknown

CVE-2023-25940

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.
Attacker Value
Unknown

CVE-2023-25536

Disclosure Date: March 02, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover.
Attacker Value
Unknown

CVE-2023-25540

Disclosure Date: February 28, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service.
Attacker Value
Unknown

CVE-2022-34445

Disclosure Date: February 11, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.
Attacker Value
Unknown

CVE-2022-34444

Disclosure Date: February 11, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak.
Attacker Value
Unknown

CVE-2022-33934

Disclosure Date: February 10, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected fields.
Attacker Value
Unknown

CVE-2022-34454

Disclosure Date: February 10, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters.
Attacker Value
Unknown

CVE-2023-22575

Disclosure Date: February 01, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges.
Attacker Value
Unknown

CVE-2023-22574

Disclosure Date: February 01, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.
Attacker Value
Unknown

CVE-2023-22573

Disclosure Date: February 01, 2023 (last updated November 08, 2023)
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.