Dell PowerScale OneFS Vulnerability Could Lead to Denial of Service
CVE-2024-25954

7.5HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
28 March 2024

Summary

Dell PowerScale OneFS versions 9.5.0.x through 9.7.0.x are vulnerable to an insufficient session expiration issue. This flaw could allow a remote, unauthenticated attacker to exploit the system, potentially leading to denial of service. Users of the affected versions are advised to apply security updates to mitigate this vulnerability.

Affected Version(s)

PowerScale OneFS 9.5.0.0 <= 9.5.0.7

PowerScale OneFS 9.6.1.0 <= 9.7.0.0

PowerScale OneFS 9.7.0.0 <= 9.7.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.