Executive brief
Dell PowerScale OneFS, an operating system used for high-performance network-attached storage, is affected by a vulnerability where system error messages may reveal sensitive information. An attacker who already has high-level administrative access to the local system could exploit this to view data they are not authorized to see. While the risk is mitigated by the requirement for high privileges, it could lead to further unauthorized data disclosure within the storage environment.
Technical details
A vulnerability classified as CWE-209 (Generation of Error Message Containing Sensitive Information) exists in Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.6 and 9.11.0.0 through 9.13.0.0. The flaw occurs when the system generates error messages that inadvertently include sensitive technical or configuration data. An attacker with high privileges (PR:H) and local access (AV:L) can trigger these errors to facilitate information disclosure. The vulnerability is addressed in OneFS versions 9.10.1.7 and 9.13.0.1 or later.
Affected products
- Dell PowerScale OneFS 9.5.0.0 through 9.10.1.6, 9.11.0.0 through 9.13.0.0
Timeline
- 2026-04-06: advisory: Initial Dell security advisory (DSA-2026-125) released
- 2026-04-08: disclosed: CVE published to NVD