PT-2022-6365 · Dell · Dell Powerscale Onefs
Published
2022-12-13
·
Updated
2023-02-08
·
CVE-2022-45098
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Dell PowerScale OneFS versions 9.0.0.x through 9.4.0.x
Description
The issue is related to the cleartext storage of sensitive information in the S3 component, potentially leading to information disclosure. An authenticated local attacker could exploit this, resulting in unauthorized access to protected information. The vulnerability is associated with the disclosure of information through log files.
Recommendations
For versions 9.0.0.x through 9.4.0.x, consider restricting access to the S3 component until a patch is available. As a temporary workaround, limit the use of the S3 component to minimize the risk of exploitation.
Fix
Insertion into Log File
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Powerscale Onefs