Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE to escalate privileges and escape the compliance guarantees. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunity.
2021-08-16T22:15:07.587
2024-11-21T05:48:40.513
Modified
CVSSv3.1: 6.0 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | emc_powerscale_onefs | ≤ 9.2.1 | Yes |
Operating System | dell | emc_powerscale_onefs | 8.2.2 | Yes |