Use of hard-coded credentials in PowerScale OneFS - CVE-2024-29170

 

Use of hard-coded credentials in PowerScale OneFS - CVE-2024-29170

Published: June 21, 2024


Vulnerability identifier: #VU92999
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29170
CWE-ID: CWE-798
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent network attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in application code. An adjacent network unauthenticated attacker can potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.


Affected software

PowerScale OneFS

How to mitigate CVE-2024-29170

Install updates from vendor's website.

PowerScale OneFS - addressed in versions 9.4.0.18, 9.7.1.0

External References

Related Security Bulletins