CVE-2026-25907
Received
Received - Intake
Account Lockout Vulnerability in Dell PowerScale OneFS Causes DoS
Publication date: 2026-03-04
Last updated on: 2026-03-04
Assigner: Dell
Description
Description
Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | powerscale_onefs | 9.13.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-645 | The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out. |