Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-45095


Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and data deletion.


Published

2023-02-01T05:15:12.630

Last Modified

2024-11-21T07:28:46.317

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dell emc_powerscale_onefs < 9.1.0.25 Yes
Operating System dell emc_powerscale_onefs < 9.2.1.18 Yes
Operating System dell emc_powerscale_onefs < 9.4.0.9 Yes

References