CVE Vulnerabilities

CVE-2022-34438

Improper Privilege Management

Published: Oct 21, 2022 | Modified: May 07, 2025
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Emc_powerscale_onefsDell9.1.0.0 (including)9.1.0.22 (including)
Emc_powerscale_onefsDell9.2.1.0 (including)9.2.1.15 (including)
Emc_powerscale_onefsDell9.3.0.0 (including)9.3.0.7 (including)
Emc_powerscale_onefsDell9.4.0.0 (including)9.4.0.5 (including)

Potential Mitigations

References