Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, information disclosure, and information tampering.
References
Configurations
History
11 Jul 2025, 12:34
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dell
Dell powerscale Onefs |
|
References | () https://www.dell.com/support/kbdoc/en-us/000326339/dsa-2025-208-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CPE | cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:* |
20 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-20 14:15
Updated : 2025-07-11 12:34
NVD link : CVE-2025-32753
Mitre link : CVE-2025-32753
JSON object : View
Products Affected
dell
- powerscale_onefs
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')