6.6

CVE-2025-43937

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellPowerscale Onefs Version < 9.5.1.5
DellPowerscale Onefs Version >= 9.6.0.0 < 9.7.1.10
DellPowerscale Onefs Version >= 9.8.0.0 < 9.10.1.3
DellPowerscale Onefs Version >= 9.11.0.0 < 9.12.0.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security_alert@emc.com 6.6 1.3 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.