PT-2022-6366 · Dell · Dell Powerscale Onefs
Published
2022-12-22
·
Updated
2023-06-27
·
CVE-2022-45097
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell PowerScale OneFS versions 9.0.0.x through 9.4.0.x
Description
The issue is related to incorrect user management, which can be exploited by a low-privileged network attacker to escalate privileges and disclose protected information. This can lead to unauthorized access and potential data breaches.
Recommendations
For versions 9.0.0.x through 9.4.0.x, update to a version that includes the fix for the incorrect user management vulnerability to prevent privilege escalation and information disclosure.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Powerscale Onefs