CVE-2024-25964: High severity Dell PowerScale OneFS vulnerability
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25964?
CVE-2024-25964 has a high severity rating as it allows remote unauthenticated attackers to potentially cause a denial of service.
How do I fix CVE-2024-25964?
To fix CVE-2024-25964, upgrade Dell PowerScale OneFS to a patched version beyond 9.7.0.1 or 9.5.0.7.
Who is affected by CVE-2024-25964?
CVE-2024-25964 affects users running Dell PowerScale OneFS versions from 9.5.0.0 to 9.5.0.7 and from 9.6.1 to 9.7.0.1.
Can CVE-2024-25964 be exploited remotely?
Yes, CVE-2024-25964 can be exploited remotely by unauthenticated attackers.
What are the potential impacts of CVE-2024-25964?
The potential impacts of CVE-2024-25964 include service disruption and denial of service to affected Dell PowerScale OneFS systems.