CVE-2026-25907
Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.26%
- CWE
- CWE-645
- Published
- 2026-03-04
- Last modified
- 2026-03-12
Affected products
- Dell PowerScale OneFS
Weakness type
Related vulnerabilities
- CVE-2026-53982 — Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association
- CVE-2025-5241 — Denial-of-Service Vulnerability in MELSEC iQ-F Series
- CVE-2025-31947 — Repeated LDAP login failures can lock an LDAP account
- CVE-2024-37028 — BIG-IP Next Central Manager vulnerability
- CVE-2024-1722 — Keycloak-core: dos via account lockout
- CVE-2023-4346