Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell powerscale Onefs |
|
| CPEs | cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell
Dell powerscale Onefs |
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Apr 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published: 2025-04-10T02:10:11.578Z
Updated: 2025-04-11T03:55:26.018Z
Reserved: 2025-02-07T06:04:04.738Z
Link: CVE-2025-26330
Updated: 2025-04-10T14:27:51.296Z
Status : Analyzed
Published: 2025-04-10T03:15:18.727
Modified: 2025-07-15T16:15:49.393
Link: CVE-2025-26330
No data.