High
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43076 | Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| CVE-2023-43087 | Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. | 4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| Third-Party Component | CVEs | CVSS Vector String |
|---|---|---|
| libxml2 | CVE-2023-29469, CVE-2023-28484 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| FreeBSD-ipv6 | CVE-2023-3107 | https://nvd.nist.gov/vuln/detail/CVE-2023-3107 |
| NTP | CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| curl | CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| OpenSSL | CVE-2023-2650 | https://nvd.nist.gov/vuln/detail/CVE-2023-2650 |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-43076 | Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| CVE-2023-43087 | Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. | 4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| Third-Party Component | CVEs | CVSS Vector String |
|---|---|---|
| libxml2 | CVE-2023-29469, CVE-2023-28484 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| FreeBSD-ipv6 | CVE-2023-3107 | https://nvd.nist.gov/vuln/detail/CVE-2023-3107 |
| NTP | CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| curl | CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534 | See NVD link below for individual scores for each CVE. http://nvd.nist.gov/ |
| OpenSSL | CVE-2023-2650 | https://nvd.nist.gov/vuln/detail/CVE-2023-2650 |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2023-43087, CVE-2023-43076 | PowerScale OneFS | Version 9.2.1.0 through 9.2.1.23 | Version 9.2.1.24 or later, Version 9.4.0.15 or later, Version 9.5.0.6 or later | PowerScale OneFS Downloads Area |
| CVE-2023-29469, CVE-2023-28484, CVE-2023-43087, CVE-2023-43076 | PowerScale OneFS | Version 9.4.0.0 through 9.4.0.14 | Version 9.4.0.15 or later, Version 9.5.0.6 or later | PowerScale OneFS Downloads Area |
| CVE-2023-29469, CVE-2023-28484, CVE-2023-3107, CVE-2023-43076, CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554, CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534, CVE-2023-43087, CVE-2023-2650. | PowerScale OneFS | Version 9.5.0.0 through 9.5.0.5 | Version 9.5.0.6 or later. | PowerScale OneFS Downloads Area |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2023-43087, CVE-2023-43076 | PowerScale OneFS | Version 9.2.1.0 through 9.2.1.23 | Version 9.2.1.24 or later, Version 9.4.0.15 or later, Version 9.5.0.6 or later | PowerScale OneFS Downloads Area |
| CVE-2023-29469, CVE-2023-28484, CVE-2023-43087, CVE-2023-43076 | PowerScale OneFS | Version 9.4.0.0 through 9.4.0.14 | Version 9.4.0.15 or later, Version 9.5.0.6 or later | PowerScale OneFS Downloads Area |
| CVE-2023-29469, CVE-2023-28484, CVE-2023-3107, CVE-2023-43076, CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554, CVE-2022-43551, CVE-2023-23916, CVE-2023-23914, CVE-2023-23915, CVE-2023-27534, CVE-2023-43087, CVE-2023-2650. | PowerScale OneFS | Version 9.5.0.0 through 9.5.0.5 | Version 9.5.0.6 or later. | PowerScale OneFS Downloads Area |
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-11-01 | Initial Release |