PT-2024-6291 · Dell · Dell Powerscale Onefs
Published
2024-08-30
·
Updated
2024-09-03
·
CVE-2024-39578
CVSS v2.0
6.4
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1
Description
The issue is related to a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service and information tampering.
Recommendations
For Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1, consider restricting access to the vulnerable system until a patch is available. As a temporary workaround, limit the privileges of local users to minimize the risk of exploitation.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Powerscale Onefs