CVE-2022-34445
11.02.2023, 01:23
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.Enginsight
Vendor | Product | Version |
---|---|---|
dell | powerscale_onefs | 8.2.0 |
dell | powerscale_onefs | 8.2.1 |
dell | powerscale_onefs | 8.2.2 |
dell | powerscale_onefs | 9.0.0 |
dell | powerscale_onefs | 9.1.0 |
dell | powerscale_onefs | 9.1.1 |
dell | powerscale_onefs | 9.2.0 |
dell | powerscale_onefs | 9.2.1 |
dell | powerscale_onefs | 9.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-261 - Weak Encoding for PasswordObscuring a password with a trivial encoding does not protect the password.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.