PT-2022-16679 · Dell · Powerscale Onefs

Published

2022-04-12

·

Updated

2022-04-20

·

CVE-2022-24411

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerScale OneFS versions 8.2.2 and above
Description A local attacker with ISI PRIV LOGIN SSH and/or ISI PRIV LOGIN CONSOLE could potentially exploit this issue, leading to elevation of privilege. This could potentially allow users to circumvent PowerScale Compliance Mode guarantees.
Recommendations For versions 8.2.2 and above, consider restricting access to ISI PRIV LOGIN SSH and ISI PRIV LOGIN CONSOLE privileges until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24411

Affected Products

Powerscale Onefs