Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to code execution, denial of service, elevation of privileges, and information disclosure.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Dell Powerscale_Onefs
cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:*
|
— |
9.10.1.6
|
|
Dell Powerscale_Onefs
cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:*
|
9.11.0.0
|
9.13.0.0
|