跳转至主要内容
  • 快速、轻松地下订单
  • 查看订单并跟踪您的发货状态
  • 创建并访问您的产品列表
  • 使用“Company Administration”(公司管理),管理Dell EMC站点、产品和产品级联系人。

文章编号: 000207863


DSA-2023-001: Dell PowerScale OneFS Security Updates for Multiple Security Vulnerabilities

摘要: Dell PowerScale remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

文章内容


影响

High

详情

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-22575 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user may potentially exploit this vulnerability, leading to information disclosure and escalation of privileges. 8.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-22574 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs from the cluster may potentially exploit this vulnerability, leading to Information disclosure and denial of service. 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies. 
CVE-2023-22573 Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker may potentially exploit this vulnerability, leading to sensitive information disclosure. 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-22572 Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker may potentially exploit this vulnerability, leading to system takeover. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-22575 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user may potentially exploit this vulnerability, leading to information disclosure and escalation of privileges. 8.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-22574 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs from the cluster may potentially exploit this vulnerability, leading to Information disclosure and denial of service. 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies. 
CVE-2023-22573 Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker may potentially exploit this vulnerability, leading to sensitive information disclosure. 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-22572 Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker may potentially exploit this vulnerability, leading to system takeover. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies 建议所有客户考虑 CVSS 基本分数以及任何相关的时间和环境分数,这可能会影响与特定安全漏洞相关的潜在严重程度。

受影响的产品和补救措施

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2023-22575 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area
CVE-2023-22574 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area
CVE-2023-22573 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area
CVE-2023-22572 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area

CVEs Addressed Product Affected Versions Updated Versions Link to Update
CVE-2023-22575 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area
CVE-2023-22574 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area
CVE-2023-22573 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area
CVE-2023-22572 PowerScale OneFS 9.1.0.0 through 9.1.0.26
9.2.1.0 through 9.2.1.19
9.4.0.0 through 9.4.0.10
Download and install the latest RUP.
>= 9.1.0.27
>= 9.2.1.20
>= 9.4.0.11
PowerScale OneFS Downloads Area
Any other version Upgrade your version of PowerScale OneFS. PowerScale OneFS Downloads Area

NOTE: All above CVEs are addressed in the newly released PowerScale OneFS version 9.5.0.0.

修订历史记录

RevisionDateDescription
1.02023-01-31 Initial Release
2.02023-07-10Updated for enhanced presentation with no changes to content 

相关信息


文章属性


受影响的产品

PowerScale OneFS

上次发布日期

10 7月 2023

版本

3

文章类型

Dell Security Advisory