PT-2022-16679 · Dell · Powerscale Onefs
Published
2022-04-12
·
Updated
2022-04-20
·
CVE-2022-24411
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell PowerScale OneFS versions 8.2.2 and above
Description
A local attacker with
ISI PRIV LOGIN SSH and/or ISI PRIV LOGIN CONSOLE could potentially exploit this issue, leading to elevation of privilege. This could potentially allow users to circumvent PowerScale Compliance Mode guarantees.Recommendations
For versions 8.2.2 and above, consider restricting access to
ISI PRIV LOGIN SSH and ISI PRIV LOGIN CONSOLE privileges until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Powerscale Onefs