Vulnerabilities > Dell > EMC Powerscale Onefs > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-04 CVE-2023-25942 Unspecified vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability.
network
low complexity
dell
6.5
2023-02-10 CVE-2022-33934 Cross-site Scripting vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities.
network
low complexity
dell CWE-79
4.8
2023-02-10 CVE-2022-34454 Out-of-bounds Write vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow.
local
low complexity
dell CWE-787
6.7
2023-02-01 CVE-2023-22573 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool.
local
low complexity
dell CWE-532
5.5
2023-02-01 CVE-2022-45098 Cleartext Storage of Sensitive Information vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component.
local
low complexity
dell CWE-312
5.5
2023-02-01 CVE-2022-45095 Command Injection vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability.
local
low complexity
dell CWE-77
6.7
2023-02-01 CVE-2022-45096 Improper Restriction of Rendered UI Layers or Frames vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue.
network
low complexity
dell CWE-1021
6.5
2022-10-21 CVE-2022-31239 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability.
local
low complexity
dell CWE-532
4.4
2022-10-21 CVE-2022-34437 OS Command Injection vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability.
local
low complexity
dell CWE-78
6.7
2022-10-21 CVE-2022-34438 Improper Privilege Management vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error.
local
low complexity
dell CWE-269
6.7