First published: Tue Apr 12 2022(Updated: )
Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to circumvent PowerScale Compliance Mode guarantees.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC PowerScale OneFS | >=8.2.2<=9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell PowerScale OneFS vulnerability is CVE-2022-24411.
CVE-2022-24411 has a severity value of 7.8 which is considered high.
The affected software for CVE-2022-24411 is Dell PowerScale OneFS version 8.2.2 and above.
CVE-2022-24411 could allow a local attacker with specific privileges to elevate their privileges on Dell PowerScale OneFS.
CVE-2022-24411 can be exploited by a local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges.