CVE-2022-29098

EUVD-2022-33509
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
dellCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
dellpowerscale_onefs
9.0.0
dellpowerscale_onefs
9.1.0
dellpowerscale_onefs
9.1.1
dellpowerscale_onefs
9.2.0
dellpowerscale_onefs
9.2.1
dellpowerscale_onefs
9.3.0
𝑥
= Vulnerable software versions