CVE-2025-43724: Medium severity Dell PowerScale OneFS vulnerability
Published Oct 8, 2025
·Updated
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares.
Affected Software
5 affected components
Dell PowerScale OneFS<9.12.0.0
Dell PowerScale OneFS>=9.8.0.0<9.10.1.3
Dell PowerScale OneFS>=9.5.0.0<9.5.1.5
Dell PowerScale OneFS>=9.6.0<9.7.1.10
Dell PowerScale OneFS>=9.11.0.0<9.12.0.0
Event History
Oct 8, 2025
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43724?
CVE-2025-43724 has a high severity rating due to the potential for unauthorized access by privileged attackers.
2
How do I fix CVE-2025-43724?
To fix CVE-2025-43724, upgrade Dell PowerScale OneFS to version 9.12.0.0 or later.
3
What type of vulnerability is CVE-2025-43724?
CVE-2025-43724 is an authorization bypass vulnerability caused by user-controlled keys.
4
Who is affected by CVE-2025-43724?
CVE-2025-43724 affects Dell PowerScale OneFS versions prior to 9.12.0.0.
5
What can an attacker achieve by exploiting CVE-2025-43724?
By exploiting CVE-2025-43724, an attacker could gain unauthorized access to NFSv4 or SMB shares.