Executive brief
Dell PowerScale OneFS, the operating system used for high-performance scale-out storage, is affected by a security vulnerability where sensitive information is improperly recorded in system log files. A user with low-level access to the system could read these logs to discover confidential data, potentially leading to further unauthorized access or data exposure. Dell has released security updates to address this issue and recommends upgrading to a remediated version.
Technical details
This vulnerability (CWE-532) exists in Dell PowerScale OneFS due to the improper insertion of sensitive information into system log files. A local attacker with low privileges (PR:L) can exploit this by accessing and reading these log files, leading to the disclosure of sensitive system or user information. The vulnerability affects multiple branches of OneFS, specifically versions 9.5.0.0 through 9.10.1.7 and 9.11.0.0 through 9.13.0.2. Dell has released patches in versions 9.10.1.8 and 9.13.1.0. As a mitigation, Dell recommends configuring non-root users to use the OneFS restricted shell.
Affected products
- Dell PowerScale OneFS 9.5.0.0 through 9.10.1.7, 9.11.0.0 through 9.13.0.2
Timeline
- 2026-06-30: advisory: Initial Dell advisory release
- 2026-07-15: disclosed: NVD publication date