First published: Tue May 14 2024(Updated: )
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC PowerScale OneFS | >=8.2.0<=9.3.0 | |
Dell EMC PowerScale OneFS | >=9.4.0<=9.4.0.17 | |
Dell EMC PowerScale OneFS | >=9.5.0.0<9.5.0.8 | |
Dell EMC PowerScale OneFS | >=9.6.0<9.7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25965 is classified as a high severity vulnerability due to its potential to allow local high privilege attackers to exploit it.
To fix CVE-2024-25965, update your Dell PowerScale OneFS software to a patched version as recommended in Dell's security update.
CVE-2024-25965 affects Dell PowerScale OneFS versions 8.2.x through 9.7.0.2, including specific ranges within those versions.
If CVE-2024-25965 is exploited, it could lead to a denial of service condition, impacting the availability of the affected systems.
CVE-2024-25965 is considered a local vulnerability, requiring an attacker to have high privileges on the system to exploit it.