CVE-2022-33923
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
21/07/2022
Last modified:
30/07/2022
Description
Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dell:emc_powerstore_500t_firmware:*:*:*:*:*:*:*:* | 3.0.0.0-1732745 (excluding) | |
| cpe:2.3:h:dell:emc_powerstore_500t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_powerstore_1200t_firmware:*:*:*:*:*:*:*:* | 3.0.0.0-1732745 (excluding) | |
| cpe:2.3:h:dell:emc_powerstore_1200t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_powerstore_3200t_firmware:*:*:*:*:*:*:*:* | 3.0.0.0-1732745 (excluding) | |
| cpe:2.3:h:dell:emc_powerstore_3200t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_powerstore_5200t_firmware:*:*:*:*:*:*:*:* | 3.0.0.0-1732745 (excluding) | |
| cpe:2.3:h:dell:emc_powerstore_5200t:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_powerstore_9200t_firmware:*:*:*:*:*:*:*:* | 3.0.0.0-1732745 (excluding) | |
| cpe:2.3:h:dell:emc_powerstore_9200t:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



