CVE-2024-25960
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 28, 2024
Updated: Jan 9, 2025
CWE ID 319
Summary
CVE-2024-25960 is a vulnerability affecting Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x. This issue allows a local, low-privileged attacker to intercept cleartext transmissions of sensitive information. By exploiting this vulnerability, the attacker could potentially escalate their privileges, posing a significant security risk. Although the exact nature of the sensitive information is not disclosed, it is crucial that affected organizations take immediate action to mitigate this risk and update their systems to the latest version of OneFS.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Dell PowerScale OneFS
Affected Vendors
- Dell Technologies, Inc.