Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch offline.
2022-04-12T18:15:08.620
2024-11-21T06:47:01.677
Modified
CVSSv3.1: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:N/I:N/A:C
3.9
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | emc_powerscale_onefs | ≤ 9.2.1.0 | Yes |