CVE-2025-43724

EUVD-2025-33307
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
dellCNA
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
dellpowerscale_onefs
9.8.0.0 ≤
𝑥
< 9.10.1.3
dellpowerscale_onefs
9.5.0.0 ≤
𝑥
< 9.5.1.5
dellpowerscale_onefs
9.6.0 ≤
𝑥
< 9.7.1.10
dellpowerscale_onefs
9.11.0.0 ≤
𝑥
< 9.12.0.0
𝑥
= Vulnerable software versions