CVE-2022-31237: Low severity Dell EMC PowerScale OneFS vulnerability
Published Aug 22, 2022
·Updated
Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to limited information disclosure.
Affected Software
2 affected components
Dell EMC PowerScale OneFS>=9.2.0<=9.2.1.12
Dell EMC PowerScale OneFS>=9.3.0.0<=9.3.0.6
Event History
Aug 22, 2022
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Dell PowerScale OneFS vulnerability?
The vulnerability ID for this Dell PowerScale OneFS vulnerability is CVE-2022-31237.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Dell EMC PowerScale OneFS versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5.
3
How severe is this vulnerability?
This vulnerability has a severity rating of 3.3 (low).
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-281.
5
How can an attacker exploit this vulnerability?
A low privileged local attacker may potentially exploit this vulnerability to achieve limited information disclosure.