CVE-2025-23378: Low severity dell emc powerscale onefs vulnerability
Published Apr 10, 2025
·Updated
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Affected Software
2 affected components
Dell PowerScale OneFS>=9.4.0.0<=9.10.0.0
Dell PowerScale OneFS>=9.4.0<=9.10.0.0
Event History
Apr 10, 2025
CVE Published
via MITRE·02:26 AM
Data Sourced
via MITRE·02:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23378?
CVE-2025-23378 has a low severity rating due to the requirement for local access for exploitation.
2
How do I fix CVE-2025-23378?
To remediate CVE-2025-23378, update your Dell PowerScale OneFS to a version beyond 9.10.0.0.
3
Who is affected by CVE-2025-23378?
Dell PowerScale OneFS versions 9.4.0.0 through 9.10.0.0 are affected by CVE-2025-23378.
4
What type of vulnerability is CVE-2025-23378?
CVE-2025-23378 is an exposure of information through directory listing vulnerability.
5
What is the potential impact of CVE-2025-23378?
Exploitation of CVE-2025-23378 could lead to unauthorized information disclosure to a low privileged attacker.