Skip to main content

Omission of Security-relevant Information

CVE-2022-22563

Severity Medium
Score 4.4/10

Summary

Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.

  • LOW
  • LOCAL
  • HIGH
  • UNCHANGED
  • NONE
  • HIGH
  • NONE
  • NONE

CWE-223 - Omission of Security-relevant Information

The application does not record or display information that would be important for identifying the source or nature of an attack, or determining if an action is safe.

References

Advisory Timeline

  • Published