CVE-2022-34454: Buffer Overflow
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34454?
CVE-2022-34454 is a vulnerability in Dell PowerScale OneFS versions 8.2.x-9.3.x that allows a local privileged malicious user to perform a heap-based buffer overflow, potentially leading to system takeover.
Which software versions are affected by CVE-2022-34454?
Dell PowerScale OneFS versions 8.2.x to 9.3.x are affected by CVE-2022-34454.
What is the impact of CVE-2022-34454?
CVE-2022-34454 can result in system takeover if exploited by a local privileged malicious user.
How severe is CVE-2022-34454?
CVE-2022-34454 has a severity score of 6.7, which is classified as medium.
How can CVE-2022-34454 be fixed?
To mitigate CVE-2022-34454, it is recommended to upgrade Dell PowerScale OneFS to a version that is not affected by the vulnerability.