Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-22471

CVE-2025-22471: Dell PowerScale OneFS DOS Vulnerability

CVE-2025-22471 is a denial of service flaw in Dell PowerScale OneFS caused by an integer overflow. Unauthenticated attackers can exploit this remotely. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-22471 Overview

CVE-2025-22471 is an integer overflow or wraparound vulnerability [CWE-190] affecting Dell PowerScale OneFS versions 9.4.0.0 through 9.10.0.1. An unauthenticated remote attacker can exploit this flaw to trigger a denial-of-service condition on affected storage systems. The vulnerability requires user interaction to succeed, which limits attack automation but does not eliminate risk in enterprise environments. Dell published advisory DSA-2025-119 on April 10, 2025 to address this and other issues in PowerScale OneFS.

Critical Impact

Successful exploitation disrupts availability of PowerScale OneFS storage clusters, potentially impacting business-critical data services relying on the affected nodes.

Affected Products

  • Dell PowerScale OneFS 9.4.0.0 through 9.4.0.x
  • Dell PowerScale OneFS 9.5.0.0 through 9.7.0.x
  • Dell PowerScale OneFS 9.8.0.0 through 9.10.0.1

Discovery Timeline

  • 2025-04-10 - CVE-2025-22471 published to NVD
  • 2025-04-10 - Dell releases security update DSA-2025-119
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-22471

Vulnerability Analysis

CVE-2025-22471 is classified as an integer overflow or wraparound weakness [CWE-190] in the Dell PowerScale OneFS operating system. Integer overflow occurs when an arithmetic operation produces a value that exceeds the maximum value a target integer type can hold. When this happens without proper bounds checking, the resulting wraparound corrupts calculations used for memory allocation, loop counters, or buffer sizing.

In the context of PowerScale OneFS, the overflow leads to a denial-of-service condition that impacts service availability. The vulnerability does not expose confidentiality or integrity of stored data, but disrupts access to the affected cluster resources.

Root Cause

The root cause is missing or insufficient validation of integer arithmetic within a network-accessible code path in OneFS. When the calculated value wraps around, downstream logic operates on an incorrect size or index, causing the service to crash or become unresponsive. Dell's advisory DSA-2025-119 addresses the flaw by correcting the affected arithmetic and bounds handling.

Attack Vector

Exploitation is performed over the network by an unauthenticated attacker. The vulnerability requires user interaction to trigger the vulnerable code path, meaning an administrator or user must perform a specific action, such as processing attacker-supplied input, for the overflow to occur. No authentication or elevated privileges are required from the attacker. See the Dell Security Update DSA-2025-119 for vendor-published technical scope.

No public proof-of-concept exploit is available at the time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2025-22471

Indicators of Compromise

  • Unexpected service crashes, node panics, or restarts on PowerScale OneFS clusters running affected versions.
  • Gaps or anomalies in OneFS system logs coinciding with inbound network requests from untrusted sources.
  • Loss of client connectivity to SMB, NFS, or HDFS shares hosted on affected nodes without a corresponding administrative change.

Detection Strategies

  • Inventory OneFS clusters and compare running versions against the affected range 9.4.0.0 through 9.10.0.1 using isi version output.
  • Monitor OneFS cluster health telemetry for repeated daemon restarts or watchdog-triggered node reboots.
  • Correlate network flow data with node availability events to identify externally sourced traffic preceding service disruption.

Monitoring Recommendations

  • Forward OneFS audit and system logs to a centralized SIEM for retention and correlation.
  • Alert on repeated crash signatures or core dumps from OneFS service processes.
  • Track SNMP and CELOG events reporting node offline or service degraded conditions.

How to Mitigate CVE-2025-22471

Immediate Actions Required

  • Apply the OneFS update referenced in Dell advisory DSA-2025-119 to all clusters running versions 9.4.0.0 through 9.10.0.1.
  • Restrict network access to OneFS management and data interfaces to trusted administrative networks only.
  • Review recent cluster availability incidents to confirm none align with exploitation attempts.

Patch Information

Dell released security update DSA-2025-119 addressing CVE-2025-22471 across affected PowerScale OneFS releases. Customers should upgrade to a fixed version as listed in the Dell Security Update DSA-2025-119 advisory. Dell recommends applying the patch during a scheduled maintenance window because OneFS updates require rolling reboots of cluster nodes.

Workarounds

  • Enforce network segmentation and firewall rules that block untrusted sources from reaching OneFS service ports.
  • Require multi-factor authentication and jump-host access for any administrative interaction with OneFS interfaces.
  • Increase monitoring sensitivity on affected clusters until the patch is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.