CVE-2024-25960

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 28, 2024
Updated: Jan 9, 2025
CWE ID 319

Summary

CVE-2024-25960 is a vulnerability affecting Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x. This issue allows a local, low-privileged attacker to intercept cleartext transmissions of sensitive information. By exploiting this vulnerability, the attacker could potentially escalate their privileges, posing a significant security risk. Although the exact nature of the sensitive information is not disclosed, it is crucial that affected organizations take immediate action to mitigate this risk and update their systems to the latest version of OneFS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Dell PowerScale OneFS

Affected Vendors

  • Dell Technologies, Inc.