VulnerabilityModified
CVE-2022-22555
Dell EMC PowerStore, contains an OS command injection Vulnerability.
MEDIUM 6.7EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- dell/emc powerstore 500t firmware · dell/emc powerstore 1200t firmware · dell/emc powerstore 3200t firmware · dell/emc powerstore 5200t firmware · dell/emc powerstore 9200t firmware
- Source
- security_alert@emc.com
References
- https://www.dell.com/support/kbdoc/000201283Vendor Advisory
- https://www.dell.com/support/kbdoc/000201283Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.