Vulnerabilities > Dell > EMC Powerscale Onefs

DATE CVE VULNERABILITY TITLE RISK
2023-02-01 CVE-2022-45098 Cleartext Storage of Sensitive Information vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component.
local
low complexity
dell CWE-312
5.5
2023-02-01 CVE-2022-45099 Incorrect Default Permissions vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password.
local
low complexity
dell CWE-276
7.8
2023-02-01 CVE-2022-45100 Improper Certificate Validation vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability.
network
low complexity
dell CWE-295
critical
9.8
2023-02-01 CVE-2022-46679 Unspecified vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability.
network
low complexity
dell
7.5
2023-02-01 CVE-2022-45095 Command Injection vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability.
local
low complexity
dell CWE-77
6.7
2023-02-01 CVE-2022-45096 Improper Restriction of Rendered UI Layers or Frames vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue.
network
low complexity
dell CWE-1021
6.5
2023-02-01 CVE-2022-45097 Unspecified vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability.
network
low complexity
dell
8.8
2023-02-01 CVE-2022-45101 Improper Privilege Management vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS.
network
low complexity
dell CWE-269
critical
9.8
2022-10-21 CVE-2022-31239 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability.
local
low complexity
dell CWE-532
4.4
2022-10-21 CVE-2022-34437 OS Command Injection vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability.
local
low complexity
dell CWE-78
6.7