Impact
Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an insecure temporary file vulnerability that permits a low‑privileged remote attacker to exploit improper handling of temporary files. The attacker can trigger a denial of service or tamper with information stored on the system. The weakness is defined as CWE‑377, an insecure temporary file issue.
Affected Systems
Affected systems are Dell PowerScale OneFS appliances running any release from 9.12.0.0 up to and including 9.13.1.0. No other vendors or product lines are affected by this CVE as identified by Dell.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need remote network access and low privilege on the system, and would exploit the insecure temporary file handling to cause service interruption or data modification. The limited exposure and lack of a widely documented exploit path lower the immediate threat, but proper mitigation is still required.
OpenCVE Enrichment