4.4

CVE-2022-34445

Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.





Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Powerscale Onefs Version 8.2.0
Dell ≫ Powerscale Onefs Version 8.2.1
Dell ≫ Powerscale Onefs Version 8.2.2
Dell ≫ Powerscale Onefs Version 9.0.0
Dell ≫ Powerscale Onefs Version 9.1.0
Dell ≫ Powerscale Onefs Version 9.1.1
Dell ≫ Powerscale Onefs Version 9.2.0
Dell ≫ Powerscale Onefs Version 9.2.1
Dell ≫ Powerscale Onefs Version 9.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.066
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EMC 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE-261 Weak Encoding for Password

Obscuring a password with a trivial encoding does not protect the password.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://www.dell.com/support/kbdoc/en-us/000205618/dsa-2022-271
Vendor Advisory