CVE Vulnerabilities

CVE-2026-25907

Overly Restrictive Account Lockout Mechanism

Published: Mar 04, 2026 | Modified: Mar 04, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

Weakness

The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.

Affected Software

NameVendorStart VersionEnd Version
Powerscale_onefsDell9.13.0.0 (including)9.13.0.0 (including)

Potential Mitigations

References