Show filters
84 Total Results
Displaying 61-70 of 84
Sort by:
Attacker Value
Unknown

CVE-2021-36279

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to access privileged information about the cluster.
Attacker Value
Unknown

CVE-2021-21568

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An authenticated user with ISI_PRIV_LOGIN_PAPI could make un-audited and un-trackable configuration changes to settings that their roles have privileges to change.
Attacker Value
Unknown

CVE-2021-21563

Disclosure Date: June 09, 2021 (last updated February 23, 2025)
Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.
Attacker Value
Unknown

CVE-2021-21562

Disclosure Date: June 09, 2021 (last updated February 23, 2025)
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application’s direct control.
Attacker Value
Unknown

CVE-2021-21527

Disclosure Date: May 03, 2021 (last updated February 22, 2025)
Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.
Attacker Value
Unknown

CVE-2021-21550

Disclosure Date: May 03, 2021 (last updated February 22, 2025)
Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability can allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.
Attacker Value
Unknown

CVE-2020-26197

Disclosure Date: April 12, 2021 (last updated February 22, 2025)
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the authentication provider.
Attacker Value
Unknown

CVE-2021-21503

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially exploit this vulnerability, leading to potential privileges escalation.
Attacker Value
Unknown

CVE-2021-21506

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPORT and ISI_PRIV_LOGIN_PAPI privileges could potentially exploit this vulnerability, leading to potential privileges escalation.
Attacker Value
Unknown

CVE-2020-26196

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentially exploit this vulnerability resulting in the ability to write data outside of the intended file system location.