PT-2023-13405 · Dell · Dell Powerscale Onefs

Published

2023-02-10

·

Updated

2023-07-21

·

CVE-2022-34445

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell PowerScale OneFS versions 8.2.x through 9.3.x
Description The issue concerns a weak encoding for a password in Dell PowerScale OneFS. A malicious local privileged attacker may potentially exploit this, leading to information disclosure.
Recommendations For Dell PowerScale OneFS versions 8.2.x through 9.3.x, consider restricting access to sensitive information and limiting privileged user accounts until a fix is available. As a temporary workaround, restrict the use of the affected password encoding mechanism to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-34445

Affected Products

Dell Powerscale Onefs