Dell Technologies has disclosed two critical security vulnerabilities affecting its PowerScale OneFS storage platform that could allow attackers to gain unauthorized access to enterprise file systems and potentially compromise entire storage infrastructures.
The vulnerabilities, tracked as CVE-2024-53298 and CVE-2025-32753, affect PowerScale OneFS versions 9.5.0.0 through 9.10.0.1 and present significant risks to organizations relying on Dell’s enterprise storage solutions.
The most severe of these vulnerabilities carries a critical CVSS score of 9.8 and enables remote unauthenticated attackers to read, modify, and delete arbitrary files across affected systems, prompting Dell to recommend immediate upgrades to mitigate potential system compromises.
The primary security concern centers around CVE-2024-53298, a missing authorization vulnerability discovered in the Network File System (NFS) export functionality of Dell PowerScale OneFS.
This critical vulnerabilities , assigned a CVSS base score of 9.8 with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, represents one of the most severe vulnerabilities affecting enterprise storage systems in recent memory.
The vulnerability’s severity stems from its ability to be exploited remotely without any authentication requirements, making it accessible to attackers across network boundaries.
The technical nature of this vulnerability lies in the inadequate authorization controls within the NFS export mechanism, which traditionally serves as a critical component for sharing file systems across networked environments.
When successfully exploited, malicious actors can bypass normal access controls and gain unrestricted access to the underlying filesystem.
This access level effectively grants attackers the same privileges as legitimate system administrators, enabling them to perform destructive operations including data theft, file modification, and complete data deletion across the storage infrastructure.
SQL Injection vulnerability
Compounding the security challenges facing PowerScale administrators is CVE-2025-32753, which introduces an additional attack vector through improper neutralization of special elements used in SQL commands.
This SQL injection vulnerability affects the same version range as the NFS authorization flaw, creating a dual-threat scenario for organizations running vulnerable PowerScale implementations.
While this vulnerability requires local access and low-level privileges, it significantly expands the potential impact of successful initial compromises.
The SQL injection vulnerability enables attackers who have gained initial foothold access to escalate their privileges and expand their control over the storage system.
Through carefully crafted SQL commands, malicious actors can trigger denial of service conditions, extract sensitive information from the underlying database systems, and tamper with critical system data.
This secondary vulnerability effectively serves as a force multiplier for attackers who have successfully exploited the primary NFS authorization flaw or gained access through alternative means.
Dell Urges Immediate Patching
Dell Technologies has characterized the NFS authorization vulnerability as capable of fully compromising affected systems and has issued urgent recommendations for customers to upgrade their PowerScale installations at the earliest opportunity.
Security experts recommend implementing emergency patching procedures and conducting comprehensive security assessments to identify potential unauthorized access that may have already occurred before patches can be applied.
The combination of remote accessibility and the absence of authentication requirements makes this vulnerability particularly attractive to cybercriminals and advanced persistent threat actors seeking to target enterprise storage infrastructures.
The company’s advisory emphasizes the critical nature of these vulnerabilities and their potential for cascading security impacts across enterprise environments.
Organizations utilizing Dell PowerScale OneFS in versions 9.5.0.0 through 9.10.0.1 face immediate risks of data breaches, ransomware attacks, and complete system compromises.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update