Known vulnerabilities in PowerScale OneFS - page 2
Vendor:
Dell
Software:
PowerScale OneFS
Software CPE:
cpe:2.3:h:dell:powerscale_onefs:*:*:*:*:*:*:*:*
Total vulnerabilities:
159
Public exploits:
10
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.11.0.1
9.10.1.3
9.5.1.3
9.7.1.8
9.10.0.0
9.7.1.5
9.10.1.2
9.9.0.1
9.5.1.2
9.7.1.3
9.4.0.20
9.5.1.1
9.5.1.0
9.4.0.19
9.7.1.2
9.9.0.0
9.7.1.0
9.4.0.18
12.0
9.5.0.6
9.2.1.21
9.4.0.12
9.4.0.11
9.4.0.9
9.4.0.8
9.4.0.7
11.7
9.1.0.28
9.5.0.0
9.5.0.1
9.4.0.13
9.2.1.22
9.4.0.14
9.5.0.2
9.4.0.10
9.2.1.19
9.1.0.26
9.1.0.24
9.1.0.23
9.1.0.22
9.2.1.17
9.2.1.16
9.2.1.15
9.4.0.6
9.4.0.5
9.3.0.8
9.3.0.9
8.2.2
8.1.2
9.1.0
9.0.0
9.1.0.20
9.1.0.19
9.1.0.18
9.1.0.17
9.1.0.16
9.1.0.15
9.1.0.14
9.1.0.13
9.1.0.12
9.1.0.11
9.1.0.10
9.1.0.9
9.1.0.8
9.1.0.7
9.1.0.6
9.1.0.5
9.1.0.4
9.1.0.3
9.1.0.2
9.1.0.1
9.1.0.0
9.2.1.13
9.2.1.12
9.2.1.11
9.2.1.10
9.2.1.9
9.2.1.8
9.2.1.7
9.2.1.6
9.2.1.5
9.2.1.4
9.2.1.3
9.2.1.2
9.2.1.1
9.2.1.0
9.3.0.6
9.3.0.5
9.3.0.4
9.3.0.3
9.3.0.2
9.3.0.1
9.3.0.0
9.4.0.3
9.4.0.2
9.4.0.1
9.4.0.0
9.4.0.4
9.3.0.7
9.2.1.14
9.1.0.21
Vulnerabilities (159)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU106262 - Resource exhaustion CVE-2024-47239 |
CWE-400 | Medium | 9.4.0.20, 9.5.1.2, 9.7.1.3, 9.9.0.1 | 31.03.2025 |
SB2025033115 |
||
| #VU102864 - Incorrect Privilege Assignment CVE-2024-39579 |
CWE-266 | Low | 9.7.1.2, 9.9.0.0, 9.4.0.19, 9.5.1.0, 9.5.1.1 | 16.01.2025 |
SB2025011632 |
||
| #VU102863 - Improper Link Resolution Before File Access ('Link Following') CVE-2024-39578 |
CWE-59 | Low | 9.7.1.2, 9.9.0.0, 9.4.0.19, 9.5.1.0, 9.5.1.1 | 16.01.2025 |
SB2025011632 |
||
| #VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-6387 |
CWE-362 | High | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 01.07.2024 |
SB2024070144 SB2024070145 SB2024070152 and 89 more |
||
| #VU92999 - Use of Hard-coded Credentials CVE-2024-29170 |
CWE-798 | Medium | 9.4.0.18, 9.7.1.0 | 21.06.2024 |
SB2024062113 |
||
| #VU88152 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2024-24795 |
CWE-113 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 04.04.2024 |
SB2024040458 SB2024040502 SB2024040903 and 38 more |
||
| #VU88151 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2023-38709 |
CWE-113 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 04.04.2024 |
SB2024040458 SB2024040502 SB2024040903 and 62 more |
||
| #VU87685 - Resource exhaustion CVE-2024-0450 |
CWE-400 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 21.03.2024 |
SB2024032107 SB2024032110 SB2024040848 and 80 more |
||
| #VU87337 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2024-28757 |
CWE-611 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 11.03.2024 |
SB2024031135 SB2024031143 SB2024031144 and 74 more |
||
| #VU87185 - UNIX Symbolic Link (Symlink) Following CVE-2023-6597 |
CWE-61 | Low | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 07.03.2024 |
SB2024030718 SB2024030726 SB2024030727 and 88 more |
||
| #VU86231 - Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') CVE-2023-52426 |
CWE-776 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 07.02.2024 |
SB2024020750 SB2024020754 SB2024020765 and 23 more |
||
| #VU86230 - Resource exhaustion CVE-2023-52425 |
CWE-400 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 07.02.2024 |
SB2024020750 SB2024020754 SB2024020765 and 120 more |
||
| #VU85764 - Improper Authentication CVE-2023-42465 |
CWE-287 | Low | 9.4.0.18, 9.7.1.0 | 24.01.2024 |
SB2024012432 SB2024012434 SB2024012435 and 32 more |
||
| #VU83930 - NULL Pointer Dereference CVE-2023-49083 |
CWE-476 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 06.12.2023 |
SB2023120655 SB2023120656 SB2023121440 and 63 more |
||
| #VU83900 - Exposure of sensitive information to an unauthorized actor CVE-2023-46218 |
CWE-200 | Low | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 06.12.2023 |
SB2023120612 SB2023120644 SB2023120661 and 87 more |
||
| #VU83899 - Missing Encryption of Sensitive Data CVE-2023-46219 |
CWE-311 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 06.12.2023 |
SB2023120612 SB2023120644 SB2023120661 and 31 more |
||
| #VU82202 - Resource Management Errors CVE-2023-7250 |
CWE-399 | Medium | 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0 | 18.10.2023 |
SB2023101843 SB2023101846 SB2023101847 and 6 more |
||
| #VU72036 - Error Handling CVE-2023-23931 |
CWE-388 | Low | 9.4.0.18, 9.7.1.0 | 08.02.2023 |
SB2023020813 SB2023030952 SB2023031419 and 68 more |
||
| #VU59106 - Improper input validation CVE-2021-30004 |
CWE-20 | Medium | 12.0 | 29.12.2021 |
SB2021040206 SB2021040207 SB2021122905 and 6 more |
||
| #VU56063 - Memory corruption CVE-2021-3711 |
CWE-119 | High | 12.0 | 24.08.2021 |
SB2021082414 SB2021082508 SB2021082510 and 53 more |
Showing elements 21 - 40 out of 159