DSA-2022-323: Dell PowerScale OneFS Security Updates for Multiple Security Vulnerabilities
Summary: Dell PowerScale remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-46679 | Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to denial of service. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| Third-party Component | CVEs | More Information |
| curl |
CVE-2022-32208 CVE-2022-32207 CVE-2022-32206 CVE-2022-32205 CVE-2022-30115 CVE-2022-27782 CVE-2022-27781 CVE-2022-27780 CVE-2022-27779 CVE-2022-27778 |
See NVD for individual scores for each CVE. |
| zlib | CVE-2022-37434 | See NVD for more details. |
| libexpat | CVE-2022-40674 | See NVD for more details. |
Note: CVE-2022-40674 impacts compliance mode clusters.
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-46679 | Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to denial of service. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| Third-party Component | CVEs | More Information |
| curl |
CVE-2022-32208 CVE-2022-32207 CVE-2022-32206 CVE-2022-32205 CVE-2022-30115 CVE-2022-27782 CVE-2022-27781 CVE-2022-27780 CVE-2022-27779 CVE-2022-27778 |
See NVD for individual scores for each CVE. |
| zlib | CVE-2022-37434 | See NVD for more details. |
| libexpat | CVE-2022-40674 | See NVD for more details. |
Note: CVE-2022-40674 impacts compliance mode clusters.
Affected Products & Remediation
|
CVEs Addressed |
Product |
Affected Versions |
Updated Versions |
Link to Update |
|
CVE-2022-32208 CVE-2022-32207 CVE-2022-32206 CVE-2022-32205 CVE-2022-30115 CVE-2022-27782 CVE-2022-27781 CVE-2022-27780 CVE-2022-27779 CVE-2022-27778 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
|||
|
CVE-2022-37434 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
|||
|
CVE-2022-40674 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
|||
|
CVE-2022-46679 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
|
CVEs Addressed |
Product |
Affected Versions |
Updated Versions |
Link to Update |
|
CVE-2022-32208 CVE-2022-32207 CVE-2022-32206 CVE-2022-32205 CVE-2022-30115 CVE-2022-27782 CVE-2022-27781 CVE-2022-27780 CVE-2022-27779 CVE-2022-27778 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
|||
|
CVE-2022-37434 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
|||
|
CVE-2022-40674 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
|||
|
CVE-2022-46679 |
PowerScale OneFS |
9.1.0.0 through 9.1.0.25 |
Download and install the latest RUP. |
|
|
Any other version |
Upgrade your version of PowerScale OneFS. |
Revision History
| Revision | Date | Description |
| 1.0 | 2022-12-22 | Initial Release |