Impact
Dell PowerScale OneFS suffers from an insertion of sensitive information into log files. When a low‑privileged user with local access writes data to the system, the application records that data in logs without sanitization, allowing the attacker to view private information that should not be exposed. The vulnerability is classified as CWE‑532 and can compromise confidentiality by leaking stored credentials, configuration details, or other sensitive data. No elevated privileges or remote access are required for the exploitation; the attacker merely needs local, low‑privilege authentication.
Affected Systems
Systems running Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and 9.11.0.0 through 9.13.0.2 are impacted. These versions include the logging component that directly records sensitive content. All affected installations instantiate log files that may store the disclosed data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of immediate exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, reinforcing that it is not a known, actively exploited threat yet. However, the attack vector is straightforward—any local user with basic permissions can trigger the log write, rendering the weakness potentially impactful in environments where privileged accounts are abundant or poorly monitored.
OpenCVE Enrichment