Dell PowerScale OneFS Incorrect Default Permissions Vulnerability Allowing Code Execution and Privilege Escalation

Vulnerability

An incorrect default permissions vulnerability has been identified in Dell PowerScale OneFS, affecting versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1. This vulnerability allows a high-privileged attacker with local access to potentially execute code, cause a denial of service, escalate privileges, and disclose information.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution, denial of service, elevated privileges, and unauthorized information disclosure.

Remediation

Users can upgrade to version 9.10.1.6 or later, or version 9.13.0.0 or later, depending on their current version. Instructions for downloading the update are available in the PowerScale OneFS Downloads Area.

Added: Mar 4, 2026, 1:20 PM
Updated: Mar 4, 2026, 7:16 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.0
remediation
8.3
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.