Impact
Dell PowerScale OneFS suffers from an uncontrolled search path element flaw that permits a local user with high privileges to execute arbitrary commands during system operations. This vulnerability can cause denial of service, elevate a user’s effective privileges beyond their intended scope, and expose sensitive system information. The weakness is categorized as CWE‑427, which describes the unauthorized use of an environmental variable to influence program execution.
Affected Systems
The affected product is Dell PowerScale OneFS. Versions prior to 9.10.1.6 and those ranging from 9.11.0.0 through 9.12.0.1 are vulnerable. Installing any release equal to or greater than 9.10.1.6 or 9.12.0.2 resolves the issue.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate-to-high risk, while the EPSS probability is below 1%, suggesting low likelihood of active exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, but the combination of local privileged access and uncontrolled path traversal still warrants prompt attention, as it could be leveraged by an insider or compromised service account. The attack vector involves local system access with elevated rights; no remote exploitation pathways are documented.
OpenCVE Enrichment