CVE-2022-34426

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
11/10/2022
Last modified:
14/10/2022

Description

Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:container_storage_modules:*:*:*:*:*:*:*:* 1.3.0 (including) 2.0.0 (excluding)