CVE-2022-33923

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
21/07/2022
Last modified:
30/07/2022

Description

Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:emc_powerstore_500t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_500t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_1200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_3200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_5200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_powerstore_9200t_firmware:*:*:*:*:*:*:*:* 3.0.0.0-1732745 (excluding)
cpe:2.3:h:dell:emc_powerstore_9200t:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools