CVE Vulnerabilities

CVE-2022-34371

Insufficiently Protected Credentials

Published: Sep 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Emc_powerscale_onefsDell9.1.0.0 (including)9.1.0.19 (including)
Emc_powerscale_onefsDell9.2.1.0 (including)9.2.1.12 (including)
Emc_powerscale_onefsDell9.3.0.0 (including)9.3.0.6 (including)
Emc_powerscale_onefsDell9.4.0.0 (including)9.4.0.3 (including)

Potential Mitigations

References