CVE-2022-31234

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/07/2022
Last modified:
30/07/2022

Description

Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:emc_powerstore_500t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_500t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_1200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_3200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_5200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_9200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_9200t:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools