#VU92999 Use of hard-coded credentials in PowerScale OneFS


Published: 2024-06-21

Vulnerability identifier: #VU92999

Vulnerability risk: Medium

CVSSv3.1: 7.1 [CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-29170

CWE-ID: CWE-798

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
PowerScale OneFS
Hardware solutions / Firmware

Vendor: Dell

Description

The vulnerability allows an adjacent network attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in application code. An adjacent network unauthenticated attacker can potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

PowerScale OneFS: All versions


External links
http://www.dell.com/support/kbdoc/en-us/000225667/dsa-2024-210-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability