8.1

CVE-2023-22574

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

Data is provided by the National Vulnerability Database (NVD)
DellEmc Powerscale Onefs Version >= 9.1.0.0 < 9.1.0.27
DellEmc Powerscale Onefs Version >= 9.2.1.0 < 9.2.1.20
DellEmc Powerscale Onefs Version >= 9.4.0.0 < 9.4.0.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.26% 0.461
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
security_alert@emc.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.