PT-2022-15529 · Dell Emc · Dell Emc Powerscale Onefs
Published
2022-04-12
·
Updated
2022-04-20
·
CVE-2022-22560
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC PowerScale OneFS versions 8.1.x through 9.1.x
Description
The issue concerns hard-coded credentials in the software, allowing a local user with knowledge of these credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. This can be exploited to take the switch offline.
Recommendations
For versions 8.1.x through 9.1.x, consider changing the hardcoded credentials to unique, secure credentials to prevent unauthorized access to the backend ethernet switch. As a temporary workaround, restrict access to the switch to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Powerscale Onefs