CVE-2022-26868
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover by an attacker.
Affected (1)
Products: Dell: Powerstoreos
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0.0 to 2.1.1.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Powerstore T | All versions |
Dell Powerstore X | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.