CVE-2023-22574: High severity dell emc isilon onefs vulnerability
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-22574.
What is the affected software?
The affected software is Dell EMC PowerScale OneFS versions 9.0.0.x - 9.4.0.x.
What is the severity of CVE-2023-22574?
The severity of CVE-2023-22574 is high with a CVSS score of 8.1.
What is the impact of this vulnerability?
This vulnerability could lead to information disclosure and denial of service.
How can I fix this vulnerability?
To fix this vulnerability, apply the security updates provided by Dell in the following advisory: [Dell PowerScale OneFS Security Updates](https://www.dell.com/support/kbdoc/en-us/000207863/dell-powerscale-onefs-security-updates-for-multiple-security).