PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LDell Powerstore 1000t
HWDellall versionsDell Powerstore 1200t
HWDellall versionsDell Powerstore 3000t
HWDellall versionsDell Powerstore 3200q
HWDellall versionsDell Powerstore 3200t
HWDellall versionsDell Powerstore 5000t
HWDellall versionsDell Powerstore 500t
HWDellall versionsDell Powerstore 5200q
HWDellall versionsDell Powerstore 5200t
HWDellall versionsDell Powerstore 7000t
HWDellall versionsDell Powerstore 9000t
HWDellall versionsDell Powerstore 9200t
HWDellall versionsDell Powerstoreos
OSDell< 4.4.0.0-2692403
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
Related vulnerabilities
CVE-2023-32478CRITICAL9.0PL ✓same product
Dell PowerStore — zapis wrażliwych danych w plikach logów
CVE-2022-26869CRITICAL9.8PL ✓same product
Dell PowerStore — otwarty port umożliwia RCE bez uwierzytelnienia
CVE-2024-51532HIGH7.1same product
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')...
CVE-2023-32449HIGH7.2same product
Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerabili...
CVE-2022-26870HIGH7.0same product
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated atta...