CVE-2022-34397
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/02/2023
Last modified:
21/07/2023
Description
<br />
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.<br />
<br />
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dell:evasa_provider_virtual_appliance:*:*:*:*:*:*:*:* | 9.2.4.15 (excluding) | |
| cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:* | 9.2.3.6 (excluding) | |
| cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:eem:*:*:* | 9.2.4.26 (excluding) | |
| cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:* | 9.2.3.22 (excluding) | |
| cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:eem:*:*:* | 9.2.4.26 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



