CVE-2022-45095

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
01/02/2023
Last modified:
07/11/2023

Description

<br /> Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and data deletion.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.1.0.0 (including) 9.1.0.25 (excluding)
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.2.1.0 (including) 9.2.1.18 (excluding)
cpe:2.3:o:dell:emc_powerscale_onefs:*:*:*:*:*:*:*:* 9.4.0.0 (including) 9.4.0.9 (excluding)