Dell Vulnerabilities and Affected Products
Vulnerabilities associated with PowerScale OneFS.
Products
Clear product- PowerScale OneFS173 vulnerabilities
- CPG BIOS110 vulnerabilities
- Unity61 vulnerabilities
- Wyse Management Suite53 vulnerabilities
- PowerProtect Data Domain49 vulnerabilities
- PowerEdge Platform33 vulnerabilities
- SmartFabric OS10 Software28 vulnerabilities
- PowerProtect DD25 vulnerabilities
- Integrated Dell Remote Access Controller (iDRAC)24 vulnerabilities
- PowerProtect Data Manager23 vulnerabilities
- PowerStore23 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202322 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202421 vulnerabilities
- CloudLink20 vulnerabilities
- Unisphere for PowerMax19 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release18 vulnerabilities
- powerscale_onefs18 vulnerabilities
- NetWorker16 vulnerabilities
- ECS15 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202515 vulnerabilities
- Avamar14 vulnerabilities
- Alienware Command Center (AWCC)13 vulnerabilities
- ControlVault313 vulnerabilities
- ControlVault3 Plus13 vulnerabilities
- Dell OpenManage Enterprise13 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-40633HIGH | Generated title:Dell PowerScale OneFS Insertion of Sensitive Information into Log FileDell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. CWE-532Jul 15, 2026 | CVSS7.8v3.1 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49501MEDIUM | Generated title:Dell PowerScale OneFS Improper Privilege Management Elevation of PrivilegeDell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. CWE-269Jul 15, 2026 | CVSS6.7v3.1 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Dell PowerScale OneFS Insufficient Logging VulnerabilityDell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. CWE-778May 8, 2026 | CVSS3.3v3.1 | EPSS0.092% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-43937MEDIUM | Generated title:Dell PowerScale OneFS Sensitive Information in Log File VulnerabilityDell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. CWE-532Apr 16, 2026 | CVSS6.6v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43935MEDIUM | Generated title:Dell PowerScale OneFS Improper Resource Shutdown or Release Denial of Service VulnerabilityDell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. CWE-404Apr 16, 2026 | CVSS4.4v3.1 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43883MEDIUM | Generated title:Dell PowerScale OneFS Improper Check for Unusual or Exceptional Conditions Denial of ServiceDell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. CWE-754Apr 16, 2026 | CVSS4.1v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24511MEDIUM | Generated title:Dell PowerScale OneFS Error Message Information DisclosureDell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. CWE-209Apr 8, 2026 | CVSS4.4v3.1 | EPSS0.159% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27102MEDIUM | Generated title:Dell PowerScale OneFS Incorrect Privilege Assignment Local Privilege EscalationDell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. CWE-266Apr 8, 2026 | CVSS6.6v3.1 | EPSS0.091% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25907MEDIUM | Generated title:Dell PowerScale OneFS Overly Restrictive Account Lockout Mechanism Denial of Service VulnerabilityDell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. CWE-645Mar 4, 2026 | CVSS5.3v3.1 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Dell PowerScale OneFS External Control of System or Configuration Setting VulnerabilityDell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setting vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to protection mechanism bypass. CWE-15Mar 4, 2026 | CVSS3.4v3.1 | EPSS0.107% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-21424MEDIUM | Generated title:Dell PowerScale OneFS Execution with Unnecessary Privileges Elevation of PrivilegeDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. CWE-250Mar 4, 2026 | CVSS6.7v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21421MEDIUM | Generated title:Dell PowerScale OneFS Execution with Unnecessary Privileges Elevation of Privilege VulnerabilityDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. CWE-250Mar 4, 2026 | CVSS6.7v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21426MEDIUM | Generated title:Dell PowerScale OneFS Execution with Unnecessary Privileges VulnerabilityDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, elevation of privileges, and information disclosure. CWE-250Mar 4, 2026 | CVSS6.7v3.1 | EPSS0.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21423MEDIUM | Generated title:Dell PowerScale OneFS Incorrect Default Permissions VulnerabilityDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to code execution, denial of service, elevation of privileges, and information disclosure. CWE-276Mar 4, 2026 | CVSS6.7v3.1 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21425MEDIUM | Generated title:Dell PowerScale OneFS Incorrect Privilege Assignment VulnerabilityDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. CWE-266Mar 4, 2026 | CVSS6.7v3.1 | EPSS0.084% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to denial of service. CWE-367Jan 22, 2026 | CVSS3.5v3.1 | EPSS0.162% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-22280MEDIUM | Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains an incorrect permission assignment for critical resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. CWE-732Jan 22, 2026 | CVSS5.0v3.1 | EPSS0.116% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22279MEDIUM | Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information tampering. CWE-778Jan 22, 2026 | CVSS4.3v3.1 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22278HIGH | Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. CWE-307Jan 22, 2026 | CVSS8.1v3.1 | EPSS0.367% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43723MEDIUM | Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. CWE-327Nov 10, 2025 | CVSS5.9v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43724MEDIUM | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares. CWE-639Oct 8, 2025 | CVSS4.4v3.1 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36601MEDIUM | Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Information disclosure. CWE-200Sep 25, 2025 | CVSS4.0v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43722MEDIUM | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. CWE-269Sep 8, 2025 | CVSS6.7v3.1 | EPSS0.134% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30477MEDIUM | Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. CWE-327Jul 21, 2025 | CVSS4.4v3.1 | EPSS0.206% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-53298CRITICAL | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be able to read, modify, and delete arbitrary files. This vulnerability is considered critical as it can be leveraged to fully compromise the system. Dell recommends customers to upgrade at the earliest opportunity. CWE-862Jun 20, 2025 | CVSS9.8v3.1 | EPSS0.464% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |