First published: Mon Mar 25 2024(Updated: )
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC PowerScale OneFS | >=9.5.0.0<9.5.0.7 | |
Dell EMC PowerScale OneFS | >=9.6.1<9.7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25964 has a high severity rating as it allows remote unauthenticated attackers to potentially cause a denial of service.
To fix CVE-2024-25964, upgrade Dell PowerScale OneFS to a patched version beyond 9.7.0.1 or 9.5.0.7.
CVE-2024-25964 affects users running Dell PowerScale OneFS versions from 9.5.0.0 to 9.5.0.7 and from 9.6.1 to 9.7.0.1.
Yes, CVE-2024-25964 can be exploited remotely by unauthenticated attackers.
The potential impacts of CVE-2024-25964 include service disruption and denial of service to affected Dell PowerScale OneFS systems.