CVE-2023-25940: High severity dell emc isilon onefs vulnerability
Published Apr 4, 2023
·Updated
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isigatherinfo. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.
Affected Software
1 affected component
Dell EMC PowerScale OneFS=9.5.0.0
Remediation
Event History
Apr 4, 2023
CVE Published
via MITRE·10:14 AM
Data Sourced
via MITRE·10:14 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25940?
CVE-2023-25940 is a vulnerability found in Dell PowerScale OneFS version 9.5.0.0.
2
How severe is CVE-2023-25940?
CVE-2023-25940 has a severity rating of 7.8 (high).
3
How does CVE-2023-25940 affect Dell PowerScale OneFS?
CVE-2023-25940 can potentially lead to system takeover and breaks the compliance mode guarantees for Dell PowerScale OneFS version 9.5.0.0.
4
How can CVE-2023-25940 be exploited?
CVE-2023-25940 can be exploited by a high privileged local attacker.
5
How can I fix CVE-2023-25940?
To fix CVE-2023-25940, it is recommended to update to a patched version of Dell PowerScale OneFS.