CVE-2023-22574

HIGH

Dell Emc Powerscale Onefs < 9.1.0.27 - Log Information Exposure

Title source: rule
STIX 2.1

Description

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

Scores

CVSS v3 8.1
EPSS 0.0048
EPSS Percentile 65.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-532
Status published
Products (1)
dell/emc_powerscale_onefs 9.1.0.0 - 9.1.0.27
Published Feb 01, 2023
Tracked Since Feb 18, 2026