- Description
- Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.
- Source
- security_alert@emc.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 2.3
- Impact score
- 1.4
- Exploitability score
- 0.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- Severity
- LOW
- security_alert@emc.com
- CWE-778
- nvd@nist.gov
- NVD-CWE-Other
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB637D7A-A495-4C22-9064-C09E910057C0",
"versionEndExcluding": "9.2.1.25",
"versionStartIncluding": "8.2.0"
},
{
"criteria": "cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CED2F99D-0CD5-49E6-9954-6E9C7171614C",
"versionEndExcluding": "9.4.0.17",
"versionStartIncluding": "9.3.0.0"
},
{
"criteria": "cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F071B492-8628-4AEE-8F7C-607414A47C58",
"versionEndExcluding": "9.5.0.7",
"versionStartIncluding": "9.5.0.0"
},
{
"criteria": "cpe:2.3:a:dell:powerscale_onefs:9.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A64A1FA-6F4B-4116-BC72-5AA79D25A85A"
}
],
"operator": "OR"
}
]
}
]