CVE-2022-34438: Medium severity dell emc isilon onefs vulnerability
Published Oct 21, 2022
·Updated
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.
Affected Software
4 affected components
Dell EMC PowerScale OneFS>=9.1.0.0<=9.1.0.22
Dell EMC PowerScale OneFS>=9.2.1.0<=9.2.1.15
Dell EMC PowerScale OneFS>=9.3.0.0<=9.3.0.7
Dell EMC PowerScale OneFS>=9.4.0.0<=9.4.0.5
Remediation
Event History
Oct 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Dell PowerScale OneFS vulnerability?
The vulnerability ID for this Dell PowerScale OneFS vulnerability is CVE-2022-34438.
2
What is the severity level of CVE-2022-34438?
The severity level of CVE-2022-34438 is medium with a CVSS score of 6.7.
3
How can this vulnerability be exploited?
This vulnerability can be exploited by a local authenticated malicious user with high privileges, potentially leading to full system compromise.
4
Which versions of Dell PowerScale OneFS are affected by this vulnerability?
Dell PowerScale OneFS versions 8.2.x-9.4.0.x are affected by this vulnerability.
5
How can I fix CVE-2022-34438?
To fix CVE-2022-34438, apply the security update provided by Dell EMC PowerScale OneFS.