Dell Technologies has issued an urgent security advisory to its users, warning of several critical vulnerabilities in its PowerScale OneFS operating system.
These flaws, if exploited, could allow attackers to take over high-privileged user accounts, bypass authorization controls, and disrupt system operations.
The vulnerabilities, tracked under multiple CVEs, range in severity and attack vectors.
They span versions of PowerScale OneFS from 9.4.0.0 to 9.10.1.0, with potential impacts including account takeover, unauthorized access, and denial of service.
Dell urges all PowerScale OneFS users to upgrade their systems to the latest remediated versions to protect against these critical vulnerabilities.
Below is a summary of the affected products, versions, and remediation details:
CVEs Addressed | Product | Affected Versions | Remediated Versions |
CVE-2025-23378 | PowerScale OneFS | 9.4.0.0 through 9.10.0.0 | 9.10.1.1 or later |
CVE-2025-26479, CVE-2025-26330, CVE-2025-22471 | PowerScale OneFS | 9.4.0.0 through 9.10.0.1 | 9.10.1.1 or later |
CVE-2025-26480 | PowerScale OneFS | 9.5.0.0 through 9.10.0.0 | 9.10.1.1 or later |
CVE-2025-22471 | PowerScale OneFS | 9.4.0.0 through 9.4.0.20 | 9.4.0.21 or later |
Dell strongly recommends updating affected systems immediately to prevent exploitation.
Admins should check their current software versions and apply the patches available in the PowerScale OneFS Downloads Area.
These vulnerabilities highlight the importance of maintaining regular software updates to prevent serious security risks.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
Verizon Business's 2025 Data Breach Investigations Report (DBIR), released on April 24, 2025, paints a…
A recent cyber espionage campaign by the notorious Lazarus Advanced Persistent Threat (APT) group, tracked…
In a alarming cybersecurity breach uncovered by Cisco Talos in 2023, a critical infrastructure enterprise…
In a startling revelation from Microsoft Threat Intelligence, threat actors are increasingly targeting unsecured Kubernetes…
A recently uncovered cyberattack campaign has brought steganography back into the spotlight, showcasing the creative…
Threat actors exploited a zero-day vulnerability in Ivanti Connect Secure, identified as CVE-2025-0282, to deploy…