CVE-2022-45099: High severity dell emc isilon onefs vulnerability
Published Feb 1, 2023
·Updated
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise
Affected Software
4 affected components
Dell EMC PowerScale OneFS>=9.1.0.0<9.1.0.24
Dell EMC PowerScale OneFS>=9.2.1.0<9.2.1.18
Dell EMC PowerScale OneFS>=9.3.0.0<9.3.0.7
Dell EMC PowerScale OneFS>=9.4.0.0<9.4.0.9
Event History
Feb 1, 2023
CVE Published
via MITRE·05:03 AM
Data Sourced
via MITRE·05:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-45099?
CVE-2022-45099 is a vulnerability in Dell PowerScale OneFS versions 8.2.x-9.4.x that allows a malicious and privileged local attacker to compromise the system.
2
How severe is CVE-2022-45099?
CVE-2022-45099 has a severity score of 7.8, which is considered high.
3
Which versions of Dell PowerScale OneFS are affected?
Dell PowerScale OneFS versions 8.2.x-9.4.x are affected by CVE-2022-45099.
4
How can CVE-2022-45099 be exploited?
CVE-2022-45099 can be exploited by a malicious and privileged local attacker.
5
Is there a fix for CVE-2022-45099?
Yes, Dell has released security updates to address CVE-2022-45099. Please refer to the Dell EMC PowerScale OneFS security advisory for more information.