First published: Fri Feb 10 2023(Updated: )
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerScale OneFS | =8.2.0 | |
Dell PowerScale OneFS | =8.2.1 | |
Dell PowerScale OneFS | =8.2.2 | |
Dell PowerScale OneFS | =9.0.0 | |
Dell PowerScale OneFS | =9.1.0 | |
Dell PowerScale OneFS | =9.1.1 | |
Dell PowerScale OneFS | =9.2.0 | |
Dell PowerScale OneFS | =9.2.1 | |
Dell PowerScale OneFS | =9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell PowerScale OneFS vulnerability is CVE-2022-34445.
The severity level of CVE-2022-34445 is medium, with a severity value of 4.4.
Dell PowerScale OneFS versions 8.2.x through 9.3.x are affected by CVE-2022-34445.
CVE-2022-34445 may potentially lead to information disclosure if exploited by a malicious local privileged attacker.
Yes, Dell has released a security advisory (DSA-2022-271) with guidance on how to mitigate the vulnerability.