6.7
CVE-2022-34438
- EPSS 0.04%
- Veröffentlicht 21.10.2022 18:15:09
- Zuletzt bearbeitet 07.05.2025 16:15:20
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Emc Powerscale Onefs Version >= 9.1.0.0 <= 9.1.0.22
Dell ≫ Emc Powerscale Onefs Version >= 9.2.1.0 <= 9.2.1.15
Dell ≫ Emc Powerscale Onefs Version >= 9.3.0.0 <= 9.3.0.7
Dell ≫ Emc Powerscale Onefs Version >= 9.4.0.0 <= 9.4.0.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.113 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| security_alert@emc.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.