CVE-2023-25941

EUVD-2023-29829
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability breaks the compliance mode guarantee.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
dellCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
dellemc_powerscale_onefs
9.1.0.0 ≤
𝑥
≤ 9.1.0.28
dellemc_powerscale_onefs
9.2.1.0 ≤
𝑥
< 9.2.1.22
dellemc_powerscale_onefs
9.4.0.0 ≤
𝑥
< 9.4.0.13
𝑥
= Vulnerable software versions