Vulnerabilities > Dell > EMC Powerscale Onefs

DATE CVE VULNERABILITY TITLE RISK
2021-08-16 CVE-2021-36281 Incorrect Permission Assignment for Critical Resource vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability.
network
low complexity
dell CWE-732
8.8
2021-08-16 CVE-2021-36282 Use of Uninitialized Resource vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability.
local
low complexity
dell CWE-908
3.3
2021-08-03 CVE-2021-21562 Untrusted Search Path vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability.
local
low complexity
dell CWE-426
4.4
2021-08-03 CVE-2021-21563 Improper Check for Unusual or Exceptional Conditions vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.
network
low complexity
dell CWE-754
6.5
2021-07-29 CVE-2020-5353 Incorrect Default Permissions vulnerability in Dell EMC Isilon Onefs and EMC Powerscale Onefs
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory.
network
low complexity
dell CWE-276
8.8
2021-07-28 CVE-2020-26180 Incorrect Default Permissions vulnerability in Dell EMC Isilon Onefs and EMC Powerscale Onefs
Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotesupport user account.
network
low complexity
dell CWE-276
8.8
2021-05-06 CVE-2021-21527 OS Command Injection vulnerability in Dell EMC Powerscale Onefs 9.0.0.0/9.1.0.0
Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability.
local
low complexity
dell CWE-78
6.7
2021-05-06 CVE-2021-21550 OS Command Injection vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability.
local
low complexity
dell CWE-78
6.7
2021-04-20 CVE-2020-26197 Cleartext Transmission of Sensitive Information vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability.
network
low complexity
dell CWE-319
critical
9.1
2021-03-08 CVE-2021-21506 Improper Input Validation vulnerability in Dell EMC Powerscale Onefs 8.1.2/8.2.2/9.1.0
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler.
network
low complexity
dell CWE-20
8.8