Vulnerabilities (CVE)

Filtered by vendor Dell Subscribe
Filtered by product Emc Powerscale Onefs
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-34371 1 Dell 1 Emc Powerscale Onefs 2023-08-08 N/A 9.8 CRITICAL
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.
CVE-2021-21502 1 Dell 1 Emc Powerscale Onefs 2022-07-12 7.5 HIGH 9.8 CRITICAL
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially exploit this vulnerability, giving them access to the same things they had before account expiration. This may by a high privileged account and hence Dell recommends customers upgrade at the earliest opportunity.
CVE-2020-26197 1 Dell 1 Emc Powerscale Onefs 2021-04-29 6.4 MEDIUM 9.1 CRITICAL
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the authentication provider.