CVE-2024-25959: High severity Dell PowerScale OneFS vulnerability
Published Mar 28, 2024
·Updated
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.
Affected Software
3 affected components
Dell PowerScale OneFS>=9.4.0<9.4.0.17
Dell PowerScale OneFS>=9.5.0.0<9.5.0.8
Dell PowerScale OneFS>=9.6.1<9.7.0.2
Event History
Mar 28, 2024
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25959?
CVE-2024-25959 is classified as a low severity vulnerability.
2
How do I fix CVE-2024-25959?
To remediate CVE-2024-25959, upgrade Dell PowerScale OneFS to versions 9.4.0.18, 9.5.0.9, or 9.7.0.3 or later.
3
Who is affected by CVE-2024-25959?
CVE-2024-25959 affects users running Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x.
4
What type of vulnerability is CVE-2024-25959?
CVE-2024-25959 is an insertion of sensitive information into log file vulnerability.
5
Can an attacker exploit CVE-2024-25959 remotely?
CVE-2024-25959 requires local access to be exploited by a low privileged attacker.