Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Emc_powerscale_onefs | Dell | 9.1.0.0 (including) | 9.1.0.24 (excluding) |
Emc_powerscale_onefs | Dell | 9.2.1.0 (including) | 9.2.1.18 (excluding) |
Emc_powerscale_onefs | Dell | 9.3.0.0 (including) | 9.3.0.7 (excluding) |
Emc_powerscale_onefs | Dell | 9.4.0.0 (including) | 9.4.0.9 (excluding) |