Known vulnerabilities in PowerScale OneFS - page 3

Vendor: Dell
Software CPE: cpe:2.3:h:dell:powerscale_onefs:*:*:*:*:*:*:*:*
Total vulnerabilities: 159
Public exploits: 10
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PowerScale OneFS PowerScale OneFS is affected by 159 known vulnerabilities: 22 high, 58 medium, 79 low Critical High Medium Low

Vulnerabilities (159)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU81721 - Exposure of resource to wrong sphere
CVE-2023-25536
CWE-668 Low
No
No
- 10.10.2023 SB20231010104
#VU81720 - Incorrect Default Permissions
CVE-2023-25540
CWE-276 Low
No
No
- 10.10.2023 SB20231010104
#VU81719 - Resource exhaustion
CVE-2023-23689
CWE-400 Medium
No
No
- 10.10.2023 SB20231010104
#VU79426 - Memory corruption
CVE-2022-34418
CWE-119 Low
No
No
11.7 11.08.2023 SB2023081124
SB2023081126
SB2023081423
and 3 more
#VU79416 - Memory corruption
CVE-2022-34417
CWE-119 Low
No
No
11.7 11.08.2023 SB2023081124
SB2023081126
SB2023081423
and 3 more
#VU76168 - Out-of-bounds write
CVE-2023-25537
CWE-787 Low
No
No
12.0 16.05.2023 SB2023051607
SB2023051609
SB2023113042
and 2 more
#VU75395 - Out-of-bounds write
CVE-2021-38578
CWE-787 Low
No
No
12.0 21.04.2023 SB2023042109
SB2023042111
SB2023042139
and 18 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
12.0 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU69392 - Resource exhaustion
CVE-2022-45061
CWE-400 Medium
No
No
9.5.0.6 16.11.2022 SB2022111650
SB2022112824
SB2022112856
and 125 more
#VU69391 - Deserialization of Untrusted Data
CVE-2022-42919
CWE-502 Low
No
No
9.5.0.6 16.11.2022 SB2022111649
SB2022111655
SB2022111656
and 35 more
#VU68887 - Integer overflow
CVE-2022-37454
CWE-190 High
Available
No
9.5.0.6 01.11.2022 SB2022110118
SB2022110119
SB2022110209
and 69 more
#VU67760 - Type conversion
CVE-2020-10735
CWE-704 Medium
No
No
9.5.0.6 29.09.2022 SB2022092968
SB2022092970
SB2022093032
and 86 more
#VU67591 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-28861
CWE-601 Low
No
No
9.5.0.6 22.09.2022 SB2022092243
SB2022092244
SB2022093032
and 76 more
#VU66207 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2021-36299
CWE-89 Medium
No
No
11.7 09.08.2022 SB2021112338
SB2022111726
SB2023081529
#VU64573 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2015-20107
CWE-78 High
No
No
9.5.0.6 22.06.2022 SB2022062206
SB2022062207
SB2022062436
and 85 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
9.5.0.6 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
9.5.0.6 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU54162 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-8670
CWE-362 Low
No
No
12.0 16.06.2021 SB2021061616
SB2021081109
SB2022111726
and 3 more
#VU50367 - Covert Timing Channel
CVE-2020-25659
CWE-385 Medium
No
No
9.5.0.6 11.01.2021 SB2020111230
SB2021052024
SB2021060319
and 18 more
#VU9883 - Exposure of sensitive information to an unauthorized actor
CVE-2017-5715
CWE-200 Low
Available
No
12.0 09.01.2018 SB2018010416
SB2018010502
SB2018011101
and 151 more


Showing elements 41 - 60 out of 159