Skip to main content
Vulnerability Database/CVE-2025-30477

CVE-2025-30477: Dell PowerScale OneFS Cryptographic Flaw

CVE-2025-30477 is a cryptographic algorithm vulnerability in Dell PowerScale OneFS that enables information disclosure by privileged attackers. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-30477 Overview

CVE-2025-30477 is an information disclosure vulnerability in Dell PowerScale OneFS caused by the use of a broken or risky cryptographic algorithm [CWE-327]. The flaw affects all OneFS versions prior to 9.11.0.0. A remote attacker holding high-privileged credentials can exploit the weakness to disclose sensitive information processed or protected by the affected cryptographic routines. Dell published fix guidance in security advisory DSA-2025-192.

Critical Impact

A remote high-privileged attacker can leverage weak cryptography in PowerScale OneFS to obtain confidential information stored or transmitted by the appliance.

Affected Products

  • Dell PowerScale OneFS versions prior to 9.11.0.0
  • Dell PowerScale clusters running vulnerable OneFS builds
  • Deployments exposing OneFS management or data services over the network

Discovery Timeline

  • 2025-07-21 - CVE-2025-30477 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-30477

Vulnerability Analysis

Dell PowerScale OneFS implements a cryptographic algorithm that is considered broken or risky. The weakness allows an authenticated attacker with high privileges and network access to derive information that the algorithm was intended to protect. Confidentiality is impacted, while integrity and availability of the OneFS cluster remain unaffected. Exploitation does not require user interaction and can be performed remotely against a reachable OneFS service.

Root Cause

The root cause is a design-level cryptographic weakness classified under CWE-327: Use of a Broken or Risky Cryptographic Algorithm. OneFS relies on an algorithm whose cryptographic guarantees are no longer sufficient to protect sensitive data. Dell addressed the issue by replacing or updating the algorithm in OneFS 9.11.0.0.

Attack Vector

Exploitation requires network reachability to the OneFS system and valid high-privileged credentials. Once authenticated, the attacker interacts with the vulnerable cryptographic function and analyzes its outputs to recover protected data. Dell has not published proof-of-concept code, and no public exploit is available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

See the Dell Security Update DSA-2025-192 for vendor-specific technical detail.

Detection Methods for CVE-2025-30477

Indicators of Compromise

  • Unexpected authenticated sessions from privileged OneFS accounts originating from unusual source addresses.
  • Anomalous access to OneFS APIs or management interfaces that handle cryptographic material.
  • Repeated queries against services that return ciphertext or cryptographic tokens.

Detection Strategies

  • Audit OneFS administrative account activity for logins from unfamiliar hosts, out-of-hours access, or lateral movement patterns.
  • Correlate privileged authentication events with subsequent API or data-access requests to identify abnormal workflows.
  • Compare running OneFS versions against 9.11.0.0 in configuration management systems to identify unpatched clusters.

Monitoring Recommendations

  • Forward OneFS audit logs and management-plane telemetry to a centralized SIEM for continuous review.
  • Alert on new or modified privileged accounts, role assignments, and RBAC changes on PowerScale clusters.
  • Monitor network flows to OneFS management interfaces and restrict them to defined administrative subnets.

How to Mitigate CVE-2025-30477

Immediate Actions Required

  • Upgrade Dell PowerScale OneFS to version 9.11.0.0 or later as specified in DSA-2025-192.
  • Rotate credentials for high-privileged OneFS accounts and any secrets that may have been handled by the weak cryptographic routine.
  • Restrict network access to OneFS management interfaces to trusted administrative networks only.

Patch Information

Dell released a fix in Dell PowerScale OneFS 9.11.0.0. Refer to the Dell Security Update DSA-2025-192 for the complete list of remediated versions and upgrade guidance.

Workarounds

  • Enforce network segmentation and firewall rules that limit OneFS access to a small set of administrative hosts.
  • Apply strict role-based access control and multi-factor authentication for all privileged OneFS accounts.
  • Increase logging verbosity and audit review cadence on OneFS clusters until the upgrade is completed.
bash
# Verify current OneFS version and confirm remediation
isi version
# Expected output for a patched cluster: 9.11.0.0 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.