DoS attacks on Dell's monitoring tool PowerScale InsightIQ conceivable
Two security vulnerabilities have compromised Dell PowerScale InsightIQ. Current versions are secured.
(Image: Alfa Photo/Shutterstock.com)
With Dell PowerScale InsightIQ, admins monitor NAS systems with the PowerScale OneFS operating system. Attackers can now use two security vulnerabilities to attack instances. Security patches provide a remedy.
Security patches available
Videos by heise
The developers list the vulnerabilities in a warning message. According to the description, remote attackers can use both vulnerabilities (CVE-2025-30475 “high”, CVE-2025-30476 “medium”) without authentication. In the first case, they can gain higher user rights. In the second case, DoS attacks are possible.
It is not yet known how attacks could take place in detail. There are currently no reports of ongoing attacks. It is not clear from the warning message which parameters can be used to identify attacked NAS systems.
The developers assure us that they have closed the vulnerabilities in version 6.0.
(des)