Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, information disclosure, and information tampering.
References
Configurations
History
11 Jul 2025, 12:34
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:* | |
First Time |
Dell powerscale Onefs
Dell |
|
References | () https://www.dell.com/support/kbdoc/en-us/000326339/dsa-2025-208-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities - Vendor Advisory |
23 Jun 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
20 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-20 14:15
Updated : 2025-07-11 12:34
NVD link : CVE-2025-32753
Mitre link : CVE-2025-32753
CVE.ORG link : CVE-2025-32753
JSON object : View
Products Affected
dell
- powerscale_onefs
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')