PT-2022-6366 · Dell · Dell Powerscale Onefs

Published

2022-12-22

·

Updated

2023-06-27

·

CVE-2022-45097

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerScale OneFS versions 9.0.0.x through 9.4.0.x
Description The issue is related to incorrect user management, which can be exploited by a low-privileged network attacker to escalate privileges and disclose protected information. This can lead to unauthorized access and potential data breaches.
Recommendations For versions 9.0.0.x through 9.4.0.x, update to a version that includes the fix for the incorrect user management vulnerability to prevent privilege escalation and information disclosure.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2023-01054
CVE-2022-45097

Affected Products

Dell Powerscale Onefs