PT-2024-3634 · Dell · Dell Powerscale Onefs

Published

2024-05-07

·

Updated

2025-01-09

·

CVE-2024-25969

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Dell PowerScale OneFS versions 8.2.x through 9.7.0.1
Description: The issue is related to an allocation of resources without limits or throttling, which could be exploited by a local unauthenticated attacker to cause a denial of service.
Recommendations: For Dell PowerScale OneFS versions 8.2.x through 9.7.0.1, consider restricting access to system resources to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider implementing throttling mechanisms for resource allocation to prevent abuse. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2024-03956
CVE-2024-25969

Affected Products

Dell Powerscale Onefs