CVE-2024-25964
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 25, 2024
Updated: Jan 9, 2025
CWE ID 385
Summary
CVE-2024-25964 is a newly disclosed vulnerability affecting Dell PowerScale OneFS versions 9.5.0.x through 9.7.0.x. This issue involves a covert timing channel, enabling an unauthenticated remote attacker to potentially exploit it for denial of service (DoS) attacks. By manipulating response times, the attacker can gain unintended information or cause system instability, resulting in service interruptions. Organizations using these Dell PowerScale versions are advised to apply the forthcoming patches to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Dell Technologies, Inc.