PT-2022-6366 · Dell · Dell Powerscale Onefs

CVE-2022-45097

·

Published

2022-12-22

·

Updated

2023-06-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerScale OneFS versions 9.0.0.x through 9.4.0.x
Description The issue is related to incorrect user management, which can be exploited by a low-privileged network attacker to escalate privileges and disclose protected information. This can lead to unauthorized access and potential data breaches.
Recommendations For versions 9.0.0.x through 9.4.0.x, update to a version that includes the fix for the incorrect user management vulnerability to prevent privilege escalation and information disclosure.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01054
CVE-2022-45097

Affected Products

Dell Powerscale Onefs