CVE-2022-45095: Command Injection
Published Feb 1, 2023
·Updated
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and data deletion.
Affected Software
3 affected components
Dell EMC PowerScale OneFS>=9.1.0.0<9.1.0.25
Dell EMC PowerScale OneFS>=9.2.1.0<9.2.1.18
Dell EMC PowerScale OneFS>=9.4.0.0<9.4.0.9
Event History
Feb 1, 2023
CVE Published
via MITRE·04:45 AM
Data Sourced
via MITRE·04:45 AM
DescriptionSeverityWeakness