CVE-2024-53298 PUBLISHED

Assigner: dell
Reserved: 20.11.2024 Published: 20.06.2025 Updated: 20.06.2025

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be able to read, modify, and delete arbitrary files. This vulnerability is considered critical as it can be leveraged to fully compromise the system. Dell recommends customers to upgrade at the earliest opportunity.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Dell
Product PowerScale OneFS
Versions Default: unaffected
  • affected from 9.5.0.0 to 9.10.0.1 (incl.)

References

Problem Types

  • CWE-862: Missing Authorization CWE