---
id: CVE-2025-43937
title: >-
  Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of
  sensitive information into log file vulnerability
summary: >-
  Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of
  sensitive information into log file vulnerability. A low privileged attacker
  with local access could potentially exploit this vulnerability, leading to the
  discl…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H'
cwe:
  - CWE-532
vendor: dell
product: powerscale_onefs
affected:
  - powerscale_onefs < 9.5.1.5
  - 'powerscale_onefs >= 9.6.0.0, < 9.7.1.10'
  - 'powerscale_onefs >= 9.8.0.0, < 9.10.1.3'
  - 'powerscale_onefs >= 9.11.0.0, < 9.12.0.0'
patched:
  - powerscale_onefs 9.12.0.0
published: '2026-04-16'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-43937'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000376214/dsa-2025-347-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
epss: 0.00141
epssPercentile: 0.02837
ingestedAt: '2026-09-30T22:27:27.759Z'
---

## Overview

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

## Affected

- `powerscale_onefs < 9.5.1.5`
- `powerscale_onefs >= 9.6.0.0, < 9.7.1.10`
- `powerscale_onefs >= 9.8.0.0, < 9.10.1.3`
- `powerscale_onefs >= 9.11.0.0, < 9.12.0.0`

## Remediation

Upgrade past the affected range:

- `powerscale_onefs 9.12.0.0`
