#VU78998 Link following in PowerScale OneFS - CVE-2023-25940
Published: August 7, 2023
PowerScale OneFS
Dell
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to Dell PowerScale OneFS contains improper link resolution before file access vulnerability in isi_gather_info. A local user can exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.