Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000218934


DSA-2023-316: Security Update for Dell PowerScale OneFS for Multiple Vulnerabilities

Summary: Dell PowerScale OneFS remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-43076 Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-43087 Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N This hyperlink is taking you to a website outside of Dell Technologies.
 
Third-Party Component CVEs CVSS Vector String
libxml2 CVE-2023-29469, CVE-2023-28484 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
FreeBSD-ipv6 CVE-2023-3107 https://nvd.nist.gov/vuln/detail/CVE-2023-3107 This hyperlink is taking you to a website outside of Dell Technologies.
NTP CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
curl CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSL CVE-2023-2650 https://nvd.nist.gov/vuln/detail/CVE-2023-2650 This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-43076 Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-43087 Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N This hyperlink is taking you to a website outside of Dell Technologies.
 
Third-Party Component CVEs CVSS Vector String
libxml2 CVE-2023-29469, CVE-2023-28484 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
FreeBSD-ipv6 CVE-2023-3107 https://nvd.nist.gov/vuln/detail/CVE-2023-3107 This hyperlink is taking you to a website outside of Dell Technologies.
NTP CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
curl CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534 See NVD link below for individual scores for each CVE. 
http://nvd.nist.gov/ This hyperlink is taking you to a website outside of Dell Technologies.
OpenSSL CVE-2023-2650 https://nvd.nist.gov/vuln/detail/CVE-2023-2650 This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2023-43087, CVE-2023-43076 PowerScale OneFS Version 9.2.1.0 through 9.2.1.23 Version 9.2.1.24 or later, Version 9.4.0.15 or later, Version 9.5.0.6 or later PowerScale OneFS Downloads Area
CVE-2023-29469, CVE-2023-28484, CVE-2023-43087, CVE-2023-43076 PowerScale OneFS Version 9.4.0.0 through 9.4.0.14 Version 9.4.0.15 or later, Version 9.5.0.6 or later PowerScale OneFS Downloads Area
CVE-2023-29469, CVE-2023-28484, CVE-2023-3107, CVE-2023-43076, CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554, CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534, CVE-2023-43087, CVE-2023-2650. PowerScale OneFS Version 9.5.0.0 through 9.5.0.5 Version 9.5.0.6 or later. PowerScale OneFS Downloads Area
CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2023-43087, CVE-2023-43076 PowerScale OneFS Version 9.2.1.0 through 9.2.1.23 Version 9.2.1.24 or later, Version 9.4.0.15 or later, Version 9.5.0.6 or later PowerScale OneFS Downloads Area
CVE-2023-29469, CVE-2023-28484, CVE-2023-43087, CVE-2023-43076 PowerScale OneFS Version 9.4.0.0 through 9.4.0.14 Version 9.4.0.15 or later, Version 9.5.0.6 or later PowerScale OneFS Downloads Area
CVE-2023-29469, CVE-2023-28484, CVE-2023-3107, CVE-2023-43076, CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554, CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534, CVE-2023-43087, CVE-2023-2650. PowerScale OneFS Version 9.5.0.0 through 9.5.0.5 Version 9.5.0.6 or later. PowerScale OneFS Downloads Area
CVE-2023-3107 is the only high severity issue and only impacting to customers that have IPV6 enabled on the front-end network.

CVE-2023-43076 only impacts customers with HDFS enabled and is only exploitable by users with ISI_PRIV_HDFS.

Any version not listed in the Affected Products and Remediation section should upgrade PowerScale OneFS to a version 9.5.0.6 or later.

We encourage all customers to adopt the LTS 2023 version which is 9.5.x code line, with the latest maintenance RUP 9.5.0.6. For more information on LTS (Long Term Support) code lines, see Dell Infrastructure Solutions Group (ISG) LTS Release Support Customer Summary

Workarounds and Mitigations


Revision History

RevisionDateDescription
1.02023-11-01Initial Release

Related Information


Article Properties


Affected Product

PowerScale OneFS

Last Published Date

09 Nov 2023

Version

6

Article Type

Dell Security Advisory