Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000206927


DSA-2022-323: Dell PowerScale OneFS Security Updates for Multiple Security Vulnerabilities

Summary: Dell PowerScale remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

Critical

Details

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-46679 Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to denial of service. 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
 
Third-party Component CVEs More Information
curl

CVE-2022-32208

CVE-2022-32207

CVE-2022-32206

CVE-2022-32205

CVE-2022-30115

CVE-2022-27782

CVE-2022-27781

CVE-2022-27780

CVE-2022-27779

CVE-2022-27778

See NVD for individual scores for each CVE.
zlib CVE-2022-37434 See NVD for more details.
libexpat CVE-2022-40674 See NVD for more details.


Note: CVE-2022-40674 impacts compliance mode clusters.
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-46679 Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to denial of service. 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
 
Third-party Component CVEs More Information
curl

CVE-2022-32208

CVE-2022-32207

CVE-2022-32206

CVE-2022-32205

CVE-2022-30115

CVE-2022-27782

CVE-2022-27781

CVE-2022-27780

CVE-2022-27779

CVE-2022-27778

See NVD for individual scores for each CVE.
zlib CVE-2022-37434 See NVD for more details.
libexpat CVE-2022-40674 See NVD for more details.


Note: CVE-2022-40674 impacts compliance mode clusters.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVEs Addressed

Product

Affected Versions

Updated Versions

Link to Update

CVE-2022-32208

CVE-2022-32207

CVE-2022-32206

CVE-2022-32205

CVE-2022-30115

CVE-2022-27782

CVE-2022-27781

CVE-2022-27780

CVE-2022-27779

CVE-2022-27778

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

PowerScale OneFS Downloads Area

Any other version

Upgrade your version of PowerScale OneFS.

CVE-2022-37434

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

Any other version

Upgrade your version of PowerScale OneFS.

CVE-2022-40674

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

Any other version

Upgrade your version of PowerScale OneFS.

CVE-2022-46679

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

Any other version

Upgrade your version of PowerScale OneFS.

CVEs Addressed

Product

Affected Versions

Updated Versions

Link to Update

CVE-2022-32208

CVE-2022-32207

CVE-2022-32206

CVE-2022-32205

CVE-2022-30115

CVE-2022-27782

CVE-2022-27781

CVE-2022-27780

CVE-2022-27779

CVE-2022-27778

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

PowerScale OneFS Downloads Area

Any other version

Upgrade your version of PowerScale OneFS.

CVE-2022-37434

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

Any other version

Upgrade your version of PowerScale OneFS.

CVE-2022-40674

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

Any other version

Upgrade your version of PowerScale OneFS.

CVE-2022-46679

PowerScale OneFS

9.1.0.0 through 9.1.0.25
9.2.1.0 through 9.2.1.18
9.4.0.0 through 9.4.0.9

Download and install the latest RUP.
> = 9.1.0.26
> = 9.2.1.19
> = 9.4.0.10

Any other version

Upgrade your version of PowerScale OneFS.

Revision History

RevisionDateDescription
1.02022-12-22 Initial Release

Related Information


Article Properties


Affected Product

PowerScale OneFS

Product

Product Security Information

Last Published Date

22 Dec 2022

Article Type

Dell Security Advisory