High
Third-Party Component |
CVE |
CVSS Base Score |
CVSS Vector String |
---|---|---|---|
OpenSSH | CVE-2023-38408 | 8.8 |
Proprietary Code CVE(s) |
Description |
CVSS Base Score |
CVSS Vector String |
---|---|---|---|
CVE-2023-44288 | Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2023-44295 | Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure. | 6.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Proprietary Code CVE(s) |
Description |
CVSS Base Score |
CVSS Vector String |
---|---|---|---|
CVE-2023-44288 | Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVE-2023-44295 | Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure. | 6.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
CVE-2023-38408 | PowerScale OneFS | Version 9.4.0.0 through 9.4.0.15
|
Version 9.4.0.16 or later |
PowerScale OneFS Downloads Area |
CVE-2023-38408 | PowerScale OneFS | Version 9.4.0.0 through 9.4.0.15 | Version 9.5.0.7 or later | PowerScale OneFS Downloads Area |
CVE-2023-38408 | PowerScale OneFS | Version 9.5.0.0 through 9.5.0.6 |
Version 9.5.0.7 or later |
PowerScale OneFS Downloads Area |
CVE-2023-44295 | PowerScale OneFS | Version 8.2.2.x through 9.6.0.x |
None |
Please refer to KB article : 000219929 : "SyncIQ and SmartSync do not preserve file quarantine attributes" |
CVE-2023-44288 | PowerScale OneFS | Version 8.2.2.x through 9.6.0.x |
None |
Please refer to KB article: 000219931 "NDMP does not automatically close the connection from the security scanner." |
CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
CVE-2023-38408 | PowerScale OneFS | Version 9.4.0.0 through 9.4.0.15
|
Version 9.4.0.16 or later |
PowerScale OneFS Downloads Area |
CVE-2023-38408 | PowerScale OneFS | Version 9.4.0.0 through 9.4.0.15 | Version 9.5.0.7 or later | PowerScale OneFS Downloads Area |
CVE-2023-38408 | PowerScale OneFS | Version 9.5.0.0 through 9.5.0.6 |
Version 9.5.0.7 or later |
PowerScale OneFS Downloads Area |
CVE-2023-44295 | PowerScale OneFS | Version 8.2.2.x through 9.6.0.x |
None |
Please refer to KB article : 000219929 : "SyncIQ and SmartSync do not preserve file quarantine attributes" |
CVE-2023-44288 | PowerScale OneFS | Version 8.2.2.x through 9.6.0.x |
None |
Please refer to KB article: 000219931 "NDMP does not automatically close the connection from the security scanner." |
Any version prior to PowerScale OneFS version 9.5.0.7 not listed in the Affected Products and Remediation section should upgrade PowerScale OneFS to a version 9.5.0.7 or later.
CVE-2023-38408: Customer on 9.6.0.x should upgrade to 9.7.0.0 or later release.
CVE | Workaround/mitigation |
---|---|
CVE-2023-38408 | Please refer to the OpenSSH security advisory Note: The user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE is potentially impacted. |
CVE-2023-44295 | Please refer the KB Link for mitigation. |
CVE-2023-44288 | Please refer the KB Link for mitigation. |
Revision |
Date |
Description |
---|---|---|
1.0 |
2023-12-05 |
Initial Release |
2.0 | 2024-03-14 | Updated Remediated version for CVE-2023-38408 |