3
CVE-2024-24901
- EPSS 0.04%
- Veröffentlicht 04.03.2024 14:15:41
- Zuletzt bearbeitet 08.01.2025 15:38:23
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Powerscale Onefs Version >= 8.2.0 < 9.2.1.25
Dell ≫ Powerscale Onefs Version >= 9.3.0.0 < 9.4.0.17
Dell ≫ Powerscale Onefs Version >= 9.5.0.0 < 9.5.0.7
Dell ≫ Powerscale Onefs Version9.6.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.095 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.3 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
|
| security_alert@emc.com | 3 | 0.5 | 2.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
|
CWE-778 Insufficient Logging
When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.