CVE-2023-22574

HIGH

Dell PowerScale OneFS 9.1.0.0-9.1.0.26 - Information Disclosure and Denial of Service via IPMI Module Log File

Title source: llm
STIX 2.1

Description

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

Scores

CVSS v3 8.1
EPSS 0.0066
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-532
Status published
Products (1)
dell/emc_powerscale_onefs 9.1.0.0 - 9.1.0.27
Published Feb 01, 2023
Tracked Since Feb 18, 2026