7.9
CVE-2024-25959
- EPSS 0.08%
- Veröffentlicht 28.03.2024 18:15:07
- Zuletzt bearbeitet 09.01.2025 16:45:52
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Powerscale Onefs Version >= 9.4.0 < 9.4.0.17
Dell ≫ Powerscale Onefs Version >= 9.5.0.0 < 9.5.0.8
Dell ≫ Powerscale Onefs Version >= 9.6.1 < 9.7.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.246 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| security_alert@emc.com | 7.9 | 2 | 5.3 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.