Known vulnerabilities in PowerScale OneFS

Vendor: Dell
Software CPE: cpe:2.3:h:dell:powerscale_onefs:*:*:*:*:*:*:*:*
Total vulnerabilities: 159
Public exploits: 10
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PowerScale OneFS PowerScale OneFS is affected by 159 known vulnerabilities: 22 high, 58 medium, 79 low Critical High Medium Low

Vulnerabilities (159)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119406 - Incorrect Permission Assignment for Critical Resource
CVE-2024-47475
CWE-732 Low
No
No
9.4.0.20, 9.5.1.1, 9.7.1.2, 9.9.0.0 09.12.2025 SB2025120935
#VU113526 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-40909
CWE-362 Low
No
No
9.10.1.3, 9.11.0.1 31.07.2025 SB2025073123
SB2025073125
SB2025073126
and 43 more
#VU110205 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-32753
CWE-89 Medium
No
No
9.5.1.3, 9.7.1.8, 9.10.1.2 04.06.2025 SB2025060454
#VU110204 - Missing Authorization
CVE-2024-53298
CWE-862 High
No
No
9.5.1.3, 9.7.1.8, 9.10.1.2 04.06.2025 SB2025060454
#VU109480 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2025-30101
CWE-367 Low
No
No
9.10.1.2 20.05.2025 SB2025052057
#VU109479 - Out-of-bounds write
CVE-2025-30102
CWE-787 Low
No
No
9.10.1.2 20.05.2025 SB2025052057
#VU108746 - Integer overflow
CVE-2025-29088
CWE-190 Medium
No
No
9.10.1.3, 9.11.0.1 07.05.2025 SB2025050709
SB2025052942
SB2025060215
and 3 more
#VU108745 - Integer overflow
CVE-2025-29087
CWE-190 Medium
No
No
9.10.1.3, 9.11.0.1 07.05.2025 SB2025050709
SB2025050710
SB2025050714
and 14 more
#VU107411 - Heap-based Buffer Overflow
CVE-2024-56406
CWE-122 High
Available
No
9.10.1.3, 9.11.0.1 14.04.2025 SB2025041424
SB2025041425
SB2025041429
and 18 more
#VU105946 - Use After Free
CVE-2025-24855
CWE-416 High
No
No
9.10.1.3, 9.11.0.1 21.03.2025 SB2025031964
SB2025032154
SB2025032155
and 63 more
#VU105879 - Use After Free
CVE-2024-55549
CWE-416 High
No
No
9.10.1.3, 9.11.0.1 19.03.2025 SB2025031964
SB2025031965
SB2025032155
and 69 more
#VU104213 - NULL Pointer Dereference
CVE-2025-27113
CWE-476 Medium
No
No
9.10.1.3, 9.11.0.1 26.02.2025 SB2025022619
SB2025022621
SB2025022890
and 32 more
#VU104099 - Use After Free
CVE-2024-56171
CWE-416 High
No
No
9.10.1.3, 9.11.0.1 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
9.10.1.3, 9.11.0.1 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2025-26465
CWE-300 Medium
No
No
9.10.1.3, 9.11.0.1 18.02.2025 SB2025021815
SB2025021830
SB2025021833
and 49 more
#VU103600 - Covert Timing Channel
CVE-2024-13176
CWE-385 Medium
No
No
9.10.1.3, 9.11.0.1 04.02.2025 SB2025020454
SB2025020456
SB2025020656
and 59 more
#VU101836 - Memory corruption
CVE-2024-53580
CWE-119 Medium
No
No
9.5.1.3, 9.7.1.8, 9.10.1.2 18.12.2024 SB2024121840
SB2025010978
SB2025010996
and 19 more
#VU96897 - Buffer Underwrite ('Buffer Underflow')
CVE-2024-45490
CWE-124 High
No
No
9.5.1.2, 9.7.1.5, 9.10.0.0 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 113 more
#VU96731 - Improper Certificate Validation
CVE-2024-39689
CWE-295 High
No
No
9.5.1.3, 9.7.1.5, 9.7.1.8, 9.10.0.0, 9.10.1.2 03.09.2024 SB2024090358
SB2024090359
SB2024090440
and 50 more
#VU95571 - Command injection
CVE-2024-6923
CWE-77 Medium
No
No
9.7.1.5, 9.10.0.0 08.08.2024 SB2024080861
SB2024080862
SB2024080863
and 144 more


Showing elements 1 - 20 out of 159