MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2022-45103

CVSS 6.5v3.1pub. 2023-01-18upd. 2024-11-21

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Dell Emc Solutions Enabler Virtual Appliance

    APP
    Dell
    < 9.2.3.6
  • Dell Emc Unisphere For Powermax

    APP
    Dell
    < 9.2.3.2210.0.0.0 – 10.0.0.5 (excl.)
  • Dell Emc Unisphere For Powermax Virtual Appliance

    APP
    Dell
    < 9.2.3.22
  • Dell Emc Vasa Provider Virtual Appliance

    APP
    Dell
    < 9.2.4.15
  • Dell Powermax Os

    OS
    Dell
    5978
  • Dell Solutions Enabler

    APP
    Dell
    10.0.0.0 – 10.0.0.5 (excl.)< 9.2.3.6
  • Dell Unisphere 360

    APP
    Dell
    < 9.2.3.12
  • Dell Vasa Provider

    APP
    Dell
    < 9.2.4.22
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2018-1183CRITICAL9.8PL ✓same product

XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)

CVE-2018-1216CRITICAL9.8PL ✓same product

Zakodowane na stałe hasło w vApp Manager — Dell EMC VMAX

CVE-2017-4997CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w EMC VASA Provider Virtual Appliance

CVE-2023-48660HIGH7.5same product

Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker c...

CVE-2023-48662HIGH7.2same product

Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious us...