CVE-2022-45098
01.02.2023, 06:15
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure.Enginsight
Vendor | Product | Version |
---|---|---|
dell | emc_powerscale_onefs | 9.1.0.0 ≤ 𝑥 < 9.1.0.25 |
dell | emc_powerscale_onefs | 9.2.1.0 ≤ 𝑥 < 9.2.1.18 |
dell | emc_powerscale_onefs | 9.4.0.0 ≤ 𝑥 < 9.4.0.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-532 - Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.