6

CVE-2022-34445

Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.





Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellPowerscale Onefs Version8.2.0
DellPowerscale Onefs Version8.2.1
DellPowerscale Onefs Version8.2.2
DellPowerscale Onefs Version9.0.0
DellPowerscale Onefs Version9.1.0
DellPowerscale Onefs Version9.1.1
DellPowerscale Onefs Version9.2.0
DellPowerscale Onefs Version9.2.1
DellPowerscale Onefs Version9.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.039
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
security_alert@emc.com 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE-261 Weak Encoding for Password

Obscuring a password with a trivial encoding does not protect the password.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.