Rewterz

ICS: Multiple Rockwell Automation Arena Vulnerabilities

April 10, 2025
Rewterz

ICS: Multiple Siemens Products Vulnerabilities

April 10, 2025

Multiple Dell Products Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2025-26479 CVSS:3.1

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.

CVE-2025-23378 CVSS:3.3

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

CVE-2025-26480 CVSS:5.3

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

CVE-2025-22471 CVSS:6.5

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

CVE-2025-26330 CVSS:7

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.

CVE-2025-27690 CVSS:9.8

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.

CVE-2025-29989 CVSS:3.1

Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.

Impact

  • Denial of Service
  • Gain Access
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2025-26479

  • CVE-2025-23378

  • CVE-2025-26480

  • CVE-2025-22471

  • CVE-2025-26330

  • CVE-2025-27690

  • CVE-2025-29989

Affected Vendors

  • Dell

Affected Products

  • Dell Client Platform BIOS
  • Dell PowerScale OneFS 9.4.0.0 - 9.10.0.0
  • Dell PowerScale OneFS 9.5.0.0 - 9.10.0.0
  • Dell PowerScale OneFS 9.4.0.0 - 9.10.0.1
  • Dell PowerScale OneFS 9.5.0.0 - 9.10.1.0

Remediation

Refer to Dell Security Advsiory for patch, upgrade, or suggested workaround information.

Dell PowerScale OneFS

Dell Client Platform BIOS

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.