PT-2022-15531 · Dell Emc · Onefs
Published
2022-04-08
·
Updated
2022-04-14
·
CVE-2022-22563
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dell EMC Powerscale OneFS versions 8.2.x through 9.2.x
Description
A high-privileged user can exploit this issue to not record information identifying the source of account information changes, as security-relevant information is omitted in /etc/master.passwd.
Recommendations
For versions 8.2.x through 9.2.x, consider restricting access to high-privileged user accounts until a patch is available to ensure that changes to account information can be properly tracked and recorded.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onefs