CVE-2025-43883 is an improper input validation vulnerability affecting Dell PowerScale OneFS versions prior to 9.12.0.0 that could allow a high-privileged local attacker to trigger a denial of service condition. The flaw stems from inadequate handling of unusual or exceptional conditions within the system. This vulnerability carries a CVSS score of 4.1 (Medium), with a high privilege requirement and high attack complexity, limiting its exploitability to only advanced attackers with existing local system access. There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the KEV catalog or the Hot List, and the EPSS score of 0.00016 indicates minimal exploitation probability compared to other known vulnerabilities. Organizations running affected OneFS versions should prioritize upgrading to version 9.12.0.0 or later, though the practical risk remains low given the stringent access requirements needed to exploit this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.5.0.0, < 9.10.1.2CPE match | cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:* | ||
>= 0, < 9.12.0.0CPE match | cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:* | ||
>= 9.5.0.0, < 9.5.1.4CPE match | cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:* | ||
>= 9.7.0.0, < 9.7.1.10CPE match | cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:* | ||
< 9.5.1.5CPE matchmatch criteria | cpe:2.3:o:dell:powerscale_onefs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.