CVE Vulnerabilities

CVE-2022-34445

Insufficiently Protected Credentials

Published: Feb 11, 2023 | Modified: Nov 07, 2023
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Powerscale_onefs Dell 8.2.0 (including) 8.2.0 (including)
Powerscale_onefs Dell 8.2.1 (including) 8.2.1 (including)
Powerscale_onefs Dell 8.2.2 (including) 8.2.2 (including)
Powerscale_onefs Dell 9.0.0 (including) 9.0.0 (including)
Powerscale_onefs Dell 9.1.0 (including) 9.1.0 (including)
Powerscale_onefs Dell 9.1.1 (including) 9.1.1 (including)
Powerscale_onefs Dell 9.2.0 (including) 9.2.0 (including)
Powerscale_onefs Dell 9.2.1 (including) 9.2.1 (including)
Powerscale_onefs Dell 9.3.0 (including) 9.3.0 (including)

Potential Mitigations

References