Impact
The vulnerability is an Improper Privilege Management flaw (CWE‑269) that allows a local attacker who already has administrative privileges in Dell PowerScale OneFS to further increase their own privileges. This escalation could enable the attacker to modify data, services, or configuration settings beyond their original authority, potentially compromising the integrity and availability of the storage appliance.
Affected Systems
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7 and 9.11.0.0 through 9.13.0.2 are affected. These versions include the identified privilege‑management flaw and are susceptible to local privilege escalation when accessed by a user with high‑privileged credentials.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, while the EPSS score of less than 1 % denotes a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access by a user who already has high‑privileged rights; no network or remote attack vector is documented. Because elevation of privileges on a storage appliance can have significant operational impact, applying the vendor‑issued firmware update that addresses this flaw is strongly recommended.
OpenCVE Enrichment