Page 4 of 49 results (0.007 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious user could potentially exploit this vulnerability, leading to denial of service/data unavailability. Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x y 9.3.0.x, contienen una vulnerabilidad de denegación de servicio. Un usuario local malicioso podría explotar esta vulnerabilidad, conllevando a una denegación de servicio o indisponibilidad de datos • https://www.dell.com/support/kbdoc/000196009 • CWE-379: Creation of Temporary File in Directory with Insecure Permissions CWE-668: Exposure of Resource to Wrong Sphere •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerability, leading to denial-of-service. Las versiones 8.2.x - 9.3.0.x de Dell PowerScale OneFS contienen una vulnerabilidad de denegación de servicio en SmartConnect. Un atacante de red sin privilegios puede explotar potencialmente esta vulnerabilidad, llevando a la denegación de servicio • https://www.dell.com/support/kbdoc/000196009 • CWE-755: Improper Handling of Exceptional Conditions •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious user could potentially exploit this vulnerability, leading to gaining write permissions on read-only files. Dell PowerScale OneFS, versiones 8.2.0-9.3.0, contiene una vulnerabilidad de manejo inapropiado de permisos insuficientes. Un usuario malicioso remoto podría explotar esta vulnerabilidad, conllevando a una obtención de permisos de escritura en archivos de sólo lectu... • https://www.dell.com/support/kbdoc/000196009 • CWE-269: Improper Privilege Management CWE-274: Improper Handling of Insufficient Privileges •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contain a missing release of memory after effective lifetime vulnerability. An authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE and ISI_PRIV_AUTH_PROVIDERS privileges could exploit this vulnerability, leading to a Denial-Of-Service. This can also impact a cluster in Compliance mode. Dell recommends to update at the earliest opportunity. Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contiene una vulnerabilidad de falta de liberación de memoria después... • https://www.dell.com/support/kbdoc/000196009 • CWE-401: Missing Release of Memory after Effective Lifetime •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, versions 9.0.0-9.3.0, contain an improper authorization of index containing sensitive information. An authenticated and privileged user could potentially exploit this vulnerability, leading to disclosure or modification of sensitive data. Dell PowerScale OneFS, versiones 9.0.0-9.3.0, contienen una autorización inapropiada de índice que contiene información confidencial. Un usuario autenticado y con privilegios podría explotar esta vulnerabilidad, conllevando a una divulgación o modifi... • https://www.dell.com/support/kbdoc/000195815 • CWE-612: Improper Authorization of Index Containing Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker could potentially exploit this denial-of-service vulnerability. Dell PowerScale OneFS, versiones 8.2.0-9.3.0, contienen una explotación de manejo inapropiado de valores perdidos. Un atacante de red no autenticado podría explotar esta vulnerabilidad de denegación de servicio • https://www.dell.com/support/kbdoc/000195815 • CWE-229: Improper Handling of Values •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts. Dell PowerScale OneFS, versiones 8.2.x-9.3.0.x, contienen una restricción inapropiada de intentos de autenticación excesivos. Un atacante remoto no autenticado podría explotar esta vulnerabilidad, conllevando a cuentas comprometidas • https://www.dell.com/support/kbdoc/000195815 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch offline. Dell EMC PowerScale OneFS 8.1.x - 9.1.x contienen credenciales embebidas. Esto permite a un usuario local con conocimiento de las credenciales iniciar sesión como usuario administrador en el conmutador ethernet backend de un c... • https://www.dell.com/support/kbdoc/000195815 • CWE-798: Use of Hard-coded Credentials •

CVSS: 6.7EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over. Dell PowerScale OneFS, versiones 8.2.2 y superiores, contienen una vulnerabilidad de divulgación de contraseñas. Un atacante local no privilegiado podría explotar esta vulnerabilidad, conllevando a una toma de la cuenta • https://www.dell.com/support/kbdoc/000195815 • CWE-522: Insufficiently Protected Credentials CWE-549: Missing Password Field Masking •

CVSS: 8.1EPSS: 0%CPEs: 1EXPL: 0

12 Apr 2022 — Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials. Dell PowerScale OneFS, versiones 8.2.x-9.3.x, contiene una comprobación inapropiada de certificados. Un atacante remoto no autenticado podría explotar esta vulnerabilidad, conllevando a una captura de credenciales administrativas por parte de un ataque de tipo man-in-the-middle • https://www.dell.com/support/kbdoc/en-us/000195815/dsa-2022-002-dell-emc-powerscale-onefs-security-update-for-multiple-vulnerabilities • CWE-295: Improper Certificate Validation •