CVE Vulnerabilities

CVE-2022-34438

Improper Privilege Management

Published: Oct 21, 2022 | Modified: Oct 24, 2022
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Emc_powerscale_onefs Dell 9.1.0.0 (including) 9.1.0.22 (including)
Emc_powerscale_onefs Dell 9.2.1.0 (including) 9.2.1.15 (including)
Emc_powerscale_onefs Dell 9.3.0.0 (including) 9.3.0.7 (including)
Emc_powerscale_onefs Dell 9.4.0.0 (including) 9.4.0.5 (including)

Potential Mitigations

References