Dell PowerScale OneFS 9.5 Improper Link Resolution (isi_gather_info)
CVE-2023-25940 Published on April 4, 2023
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees.
Vulnerability Analysis
CVE-2023-25940 is exploitable with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2023-25940 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2023-25940
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-25940 are published in Dell Emc Powerscale Onefs:
Affected Versions
Dell PowerScale OneFS Version 9.5.0.0 is affected by CVE-2023-25940Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.