PT-2024-2504 · Dell · Powerscale Onefs

Published

2024-03-28

·

Updated

2025-01-09

·

CVE-2024-25952

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x
Description The issue is related to the tracking of symbolic links in the PowerScale OneFS operating system. Exploitation of this issue may allow an attacker to cause a denial of service and impact the integrity of protected information. A local high-privileged attacker could potentially exploit this vulnerability, leading to denial of service and information tampering.
Recommendations For Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x, update to a version outside of this range to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Weakness Enumeration

Related Identifiers

BDU:2024-02485
CVE-2024-25952

Affected Products

Powerscale Onefs