Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HDell Powerstore 1000t
HWDellwszystkie wersjeDell Powerstore 1200t
HWDellwszystkie wersjeDell Powerstore 3000t
HWDellwszystkie wersjeDell Powerstore 3200q
HWDellwszystkie wersjeDell Powerstore 3200t
HWDellwszystkie wersjeDell Powerstore 5000t
HWDellwszystkie wersjeDell Powerstore 500t
HWDellwszystkie wersjeDell Powerstore 5200t
HWDellwszystkie wersjeDell Powerstore 7000t
HWDellwszystkie wersjeDell Powerstore 9000t
HWDellwszystkie wersjeDell Powerstore 9200t
HWDellwszystkie wersjeDell Powerstoreos
OSDell< 4.0.1.0-2408234
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Powiązane podatności
CVE-2023-32478CRITICAL9.0PL ✓ten sam produkt
Dell PowerStore — zapis wrażliwych danych w plikach logów
CVE-2022-26869CRITICAL9.8PL ✓ten sam produkt
Dell PowerStore — otwarty port umożliwia RCE bez uwierzytelnienia
CVE-2023-32449HIGH7.2ten sam produkt
Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerabili...
CVE-2022-26870HIGH7.0ten sam produkt
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated atta...
CVE-2022-22557HIGH7.5ten sam produkt
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running version...