← Back to CVEs
CVE-2022-34397
MEDIUM6.9
Description
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
CVE Details
CVSS v3.1 Score6.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published2/13/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
dell:evasa_provider_virtual_appliancedell:solutions_enabler_virtual_appliancedell:unisphere_for_powermax_virtual_appliance
Weaknesses (CWE)
CWE-863
References
https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-for-powermax-dell-unisphere-for-powermax-vapp-dell-solutions-enabler-vapp-dell-unisphere-360-dell-vasa-provider-vapp-and-dell-powermax-emb-mgmt-security-update-for-multiple-vulnerabilities(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.