Impact
Dell PowerScale OneFS, versions prior to 9.13.0.0, suffers from an insufficient logging vulnerability that allows an unauthenticated attacker with remote access to tamper with audit logs, thereby compromising the integrity of logged evidence.
Affected Systems
Dell PowerScale OneFS systems running any version earlier than 9.13.0.0 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate severity, and an EPSS score of less than 1%, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog. The described attack vector is remote and does not require authentication, meaning an external adversary can attempt log tampering without credentials.
OpenCVE Enrichment