CVE-2023-32449

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/06/2023
Last modified:
28/06/2023

Description

<br /> Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)
cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)
cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:* 3.5.0.0-2050321 (excluding)