CVE-2024-25952: Medium severity Dell PowerScale OneFS vulnerability
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25952?
CVE-2024-25952 has a high severity rating as it allows a local high privileged attacker to exploit the vulnerability.
How do I fix CVE-2024-25952?
To fix CVE-2024-25952, update your Dell PowerScale OneFS to a version that is not affected, such as versions later than 9.7.0.x.
What systems are affected by CVE-2024-25952?
CVE-2024-25952 affects Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x.
What type of attack can CVE-2024-25952 facilitate?
CVE-2024-25952 can potentially lead to denial of service and information tampering by a high privileged local attacker.
Is there a patch available for CVE-2024-25952?
Yes, Dell has released a security update to mitigate the vulnerabilities related to CVE-2024-25952.