CVE-2023-32492: High severity Dell PowerScale OneFS vulnerability
Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32492?
CVE-2023-32492 is a vulnerability in Dell PowerScale OneFS 9.5.0.x that allows a low-privileged attacker to disclose information or modify files due to incorrect default permissions.
How severe is CVE-2023-32492?
CVE-2023-32492 has a severity rating of 7.1 (high).
How can a low-privileged attacker exploit CVE-2023-32492?
A low-privileged attacker can exploit CVE-2023-32492 by taking advantage of the incorrect default permissions in Dell PowerScale OneFS 9.5.0.x, potentially leading to information disclosure or file modification.
What versions of Dell PowerScale OneFS are affected by CVE-2023-32492?
Dell PowerScale OneFS versions between 9.2.1.0 and 9.2.1.22, 9.4.0.0 and 9.4.0.13, and 9.5.0.0 and 9.5.0.3 are affected by CVE-2023-32492.
Where can I find more information about CVE-2023-32492?
You can find more information about CVE-2023-32492 at the following reference link: https://www.dell.com/support/kbdoc/en-us/000216717/dsa-2023-269-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities