Unauthenticated Remote Access Vulnerability in Dell PowerScale InsightIQ Could Allow Exfiltration of Arbitrary Files
CVE-2024-39581

9.8CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
10 September 2024

Summary

Dell PowerScale InsightIQ, specifically versions 5.0 through 5.1, is exposed to a vulnerability that allows unauthenticated attackers to gain unauthorized access to files and directories. This flaw can lead to the potential reading, modification, and deletion of arbitrary files stored within the system. If exploited, it poses significant risks to data integrity and confidentiality, making it imperative for users to implement security updates and patches as soon as they are available. For further information, refer to Dell's advisory on the security update.

Affected Version(s)

PowerScale InsightIQ 5.0 <= 5.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.