CVE-2023-22575: High severity dell emc isilon onefs vulnerability
Published Feb 1, 2023
·Updated
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges.
Affected Software
3 affected components
Dell EMC PowerScale OneFS>=9.1.0.0<9.1.0.27
Dell EMC PowerScale OneFS>=9.2.1.0<9.2.1.20
Dell EMC PowerScale OneFS>=9.4.0.0<9.4.0.11
Event History
Feb 1, 2023
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Dell PowerScale OneFS vulnerability?
The vulnerability ID for this Dell PowerScale OneFS vulnerability is CVE-2023-22575.
2
What is the severity of CVE-2023-22575?
The severity of CVE-2023-22575 is high with a severity value of 8.8.
3
What is the affected software for CVE-2023-22575?
The affected software for CVE-2023-22575 is Dell PowerScale OneFS version 9.0.0.x - 9.4.0.x.
4
What is the risk associated with CVE-2023-22575?
The risk associated with CVE-2023-22575 is information disclosure and escalation of privileges.
5
Is there a fix available for CVE-2023-22575?
Yes, Dell has released security updates for Dell PowerScale OneFS to address this vulnerability. Please refer to the reference link for more information.