CVE-2025-43724Medium· 4.4▾ SunlitDell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares.
powerscale_onefs >= 9.8.0.0, < 9.10.1.3powerscale_onefs >= 9.5.0.0, < 9.5.1.5powerscale_onefs >= 9.6.0, < 9.7.1.10powerscale_onefs >= 9.11.0.0, < 9.12.0.0Upgrade past the affected range:
powerscale_onefs 9.12.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-43883Medium· 4.1Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability
CVE-2025-43935Medium· 4.4Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability
CVE-2025-43937Medium· 6.6Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability
CVE-2025-43723Medium· 5.9Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability
CVE-2026-40635Medium· 5.4Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability
CVE-2026-70425Medium· 6.7Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability