EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDell Emc Vasa Provider Virtual Appliance
APPDell≤ 8.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2018-1183CRITICAL9.8PL ✓same product
XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)
CVE-2022-45103MEDIUM6.5same product
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an in...
CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor
Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)
CVE-2026-70419CRITICAL9.1same vendor
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements ...
CVE-2026-54489CRITICAL9.1PL ✓same vendor
Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta