CVE-2025-36601

Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerscale_onefs:9.11.0.0:*:*:*:*:*:*:*

History

31 Oct 2025, 14:16

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:dell:powerscale_onefs:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerscale_onefs:9.11.0.0:*:*:*:*:*:*:*
First Time Dell
Dell powerscale Onefs
References () https://www.dell.com/support/kbdoc/en-us/000353080/dsa-2025-272-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000353080/dsa-2025-272-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities - Vendor Advisory

Information

Published : 2025-09-25 15:16

Updated : 2025-10-31 14:16


NVD link : CVE-2025-36601

Mitre link : CVE-2025-36601

CVE.ORG link : CVE-2025-36601


JSON object : View

Products Affected

dell

  • powerscale_onefs
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo