Vulnerabilities > Dell > EMC Powerscale Onefs

DATE CVE VULNERABILITY TITLE RISK
2023-04-04 CVE-2023-25941 Incorrect Default Permissions vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability.
local
low complexity
dell CWE-276
7.8
2023-04-04 CVE-2023-25942 Improper Control of a Resource Through its Lifetime vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability.
network
low complexity
dell CWE-664
6.5
2023-04-04 CVE-2023-25940 Link Following vulnerability in Dell EMC Powerscale Onefs 9.5.0.0
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info.
local
low complexity
dell CWE-59
7.8
2023-02-28 CVE-2023-25540 Incorrect Default Permissions vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability.
local
low complexity
dell CWE-276
7.1
2023-02-10 CVE-2022-33934 Cross-site Scripting vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities.
network
low complexity
dell CWE-79
4.8
2023-02-10 CVE-2022-34454 Out-of-bounds Write vulnerability in Dell EMC Powerscale Onefs 9.1.0.0/9.2.1.0/9.3.0.0
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow.
local
low complexity
dell CWE-787
6.7
2023-02-01 CVE-2023-22573 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool.
local
low complexity
dell CWE-532
5.5
2023-02-01 CVE-2023-22574 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module.
network
low complexity
dell CWE-532
8.1
2023-02-01 CVE-2023-22575 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog.
network
low complexity
dell CWE-532
8.8
2023-02-01 CVE-2023-22572 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api.
local
low complexity
dell CWE-532
7.8