Unauthenticated Remote Access Vulnerability in Dell PowerScale InsightIQ Could Allow Exfiltration of Arbitrary Files
CVE-2024-39581
9.8CRITICAL
Summary
Dell PowerScale InsightIQ, specifically versions 5.0 through 5.1, is exposed to a vulnerability that allows unauthenticated attackers to gain unauthorized access to files and directories. This flaw can lead to the potential reading, modification, and deletion of arbitrary files stored within the system. If exploited, it poses significant risks to data integrity and confidentiality, making it imperative for users to implement security updates and patches as soon as they are available. For further information, refer to Dell's advisory on the security update.
Affected Version(s)
PowerScale InsightIQ 5.0 <= 5.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved