PT-2022-20631 · Dell · Dell Powerscale Onefs

Published

2022-08-22

·

Updated

2022-08-24

·

CVE-2022-31237

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell PowerScale OneFS versions 9.2.0 through 9.2.1.12 Dell PowerScale OneFS version 9.3.0.5
Description The issue is related to an improper preservation of permissions in SyncIQ, which could allow a low-privileged local attacker to potentially exploit it and lead to limited information disclosure.
Recommendations For Dell PowerScale OneFS versions 9.2.0 through 9.2.1.12, update to a version outside of the affected range to resolve the issue. For Dell PowerScale OneFS version 9.3.0.5, update to a version outside of the affected range to resolve the issue. As a temporary workaround, consider restricting access to SyncIQ to minimize the risk of exploitation.

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-31237

Affected Products

Dell Powerscale Onefs