CVE-2024-22449: High severity Dell PowerScale OneFS vulnerability
Published Feb 1, 2024
·Updated
Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access.
Affected Software
1 affected component
Dell PowerScale OneFS>=9.0.0<9.6.1
Event History
Feb 1, 2024
CVE Published
via MITRE·09:48 AM
Data Sourced
via MITRE·09:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22449?
CVE-2024-22449 is classified as a critical vulnerability due to its potential for local escalation of privileges.
2
How do I fix CVE-2024-22449?
To fix CVE-2024-22449, upgrade Dell PowerScale OneFS to version 9.6.1 or later.
3
What versions of Dell PowerScale OneFS are affected by CVE-2024-22449?
CVE-2024-22449 affects Dell PowerScale OneFS versions from 9.0.0.x up to and including 9.6.0.x.
4
Who can exploit CVE-2024-22449?
CVE-2024-22449 can be exploited by a low privileged local malicious user with access to the affected system.
5
What type of vulnerability is CVE-2024-22449?
CVE-2024-22449 is categorized as a missing authentication for critical functions vulnerability.