CVE-2025-43937: Medium severity Dell PowerScale OneFS vulnerability
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43937?
CVE-2025-43937 is classified as a low severity vulnerability.
How do I fix CVE-2025-43937?
To resolve CVE-2025-43937, upgrade to Dell PowerScale OneFS version 9.12.0.0 or later.
What type of information is exposed in CVE-2025-43937?
CVE-2025-43937 may lead to the disclosure of certain user credentials.
Can CVE-2025-43937 be exploited by unprivileged users?
CVE-2025-43937 requires local access and a low privileged attacker to exploit the vulnerability.
Which versions of Dell PowerScale OneFS are affected by CVE-2025-43937?
CVE-2025-43937 affects all versions of Dell PowerScale OneFS prior to 9.12.0.0.