Dell
Dell EMC Powerscale Onefs: vulnerabilidades y CVE
Dell EMC Powerscale Onefs tiene 84 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE84
Últimos 12 meses0
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-25942 | Media (6.5) | 0.60% | — | 4 abr 2023 | Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a… |
| CVE-2023-25941 | Alta (7.8) | 0.16% | — | 4 abr 2023 | Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of… |
| CVE-2023-25940 | Alta (7.8) | 0.21% | — | 4 abr 2023 | Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to… |
| CVE-2023-25540 | Alta (7.1) | 0.15% | — | 28 feb 2023 | Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service. |
| CVE-2022-33934 | Media (4.8) | 0.39% | — | 10 feb 2023 | Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities… |
| CVE-2022-34454 | Media (6.7) | 0.19% | — | 10 feb 2023 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode… |
| CVE-2023-22575 | Alta (8.8) | 0.63% | — | 1 feb 2023 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information… |
| CVE-2023-22574 | Alta (8.1) | 0.66% | — | 1 feb 2023 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could… |
| CVE-2023-22573 | Media (5.5) | 0.17% | — | 1 feb 2023 | Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to… |
| CVE-2023-22572 | Alta (7.8) | 0.18% | — | 1 feb 2023 | Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability,… |
| CVE-2022-46679 | Alta (7.5) | 0.77% | — | 1 feb 2023 | Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. |
| CVE-2022-45100 | Crítica (9.8) | 0.51% | — | 1 feb 2023 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of… |
| CVE-2022-45099 | Alta (7.8) | 0.19% | — | 1 feb 2023 | Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise |
| CVE-2022-45098 | Media (5.5) | 0.12% | — | 1 feb 2023 | Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to… |
| CVE-2022-45101 | Crítica (9.8) | 0.82% | — | 1 feb 2023 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to… |
| CVE-2022-45097 | Alta (8.8) | 0.41% | — | 1 feb 2023 | Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and… |
| CVE-2022-45096 | Media (6.5) | 0.49% | — | 1 feb 2023 | Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of… |
| CVE-2022-45095 | Media (6.7) | 0.64% | — | 1 feb 2023 | Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this… |
| CVE-2022-34439 | Alta (7.5) | 0.93% | — | 21 oct 2022 | Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to… |
| CVE-2022-34438 | Media (6.7) | 0.18% | — | 21 oct 2022 | Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system… |
| CVE-2022-34437 | Media (6.7) | 0.45% | — | 21 oct 2022 | Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This… |
| CVE-2022-31239 | Media (4.4) | 0.24% | — | 21 oct 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading… |
| CVE-2022-34378 | Media (5.5) | 0.20% | — | 2 sept 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this… |
| CVE-2022-34371 | Crítica (9.8) | 0.66% | — | 2 sept 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could… |
| CVE-2022-34369 | Alta (7.5) | 0.65% | — | 2 sept 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could… |
| CVE-2022-33932 | Media (5.3) | 0.85% | — | 22 ago 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotected primary channel vulnerability. An unauthenticated network malicious attacker may potentially… |
| CVE-2022-32480 | Media (6.5) | 0.86% | — | 22 ago 2022 | Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may… |
| CVE-2022-31238 | Media (5.5) | 0.18% | — | 22 ago 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process invoked with sensitive information vulnerability. A CLI user may potentially exploit this… |
| CVE-2022-31237 | Baja (3.3) | 0.25% | — | 22 ago 2022 | Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this… |
| CVE-2022-24413 | Baja (3.6) | 0.14% | — | 12 abr 2022 | Dell PowerScale OneFS, versions 8.2.2-9.3.x, contain a time-of-check-to-time-of-use vulnerability. A local user with access to the filesystem could potentially exploit this vulnerability, leading to data loss. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Dell
Secure Connect Gateway · 135Data Domain Operating System · 99Powerscale Onefs · 98Wyse Management Suite · 70Latitude 9410 Firmware · 65Latitude 5511 Firmware · 64Latitude 5411 Firmware · 64Latitude 7310 Firmware · 63Latitude 7410 Firmware · 63Latitude 5310 Firmware · 62Latitude 5400 Firmware · 62Optiplex 7080 Firmware · 62