CVE-2024-25954: Dell Powerscale Onefs

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

Affected products

  • Dell Powerscale Onefs: from 9.5.0.0, before 9.5.0.8 (fixed in 9.5.0.8); from 9.6.1, before 9.7.0.2 (fixed in 9.7.0.2)

Published 2024-03-28. Last modified 2026-06-17.