CVE-2022-22551
HIGHCVSS 8.8/10EPSS 0.39%
Last modified
CVE-2022-22551 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Appsync | < 4.4.0.0 |
References
- https://www.dell.com/support/kbdoc/000195377Patch, Vendor Advisory
- https://www.dell.com/support/kbdoc/000195377Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-22551?
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
How severe is CVE-2022-22551?
CVE-2022-22551 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2022-22551?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22545A high privileged user who has access to transaction SM59 ca…4.9
- CVE-2022-22546Due to improper HTML encoding in input control summary, an a…5.4
- CVE-2022-22547Simple Diagnostics Agent - versions 1.0 (up to version 1.57.…7.5
- CVE-2022-22549Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Cert…8.1
- CVE-2022-2255A vulnerability was found in mod_wsgi. The X-Client-IP heade…7.5
- CVE-2022-22550Dell PowerScale OneFS, versions 8.2.2 and above, contain a p…6.7
- CVE-2022-22552Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking …6.1
- CVE-2022-22553Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Res…9.8
- CVE-2022-22554Dell EMC System Update, version 1.9.2 and prior, contain an …5.5
- CVE-2022-22555Dell EMC PowerStore, contains an OS command injection Vulner…6.7
- CVE-2022-22556Dell PowerStore contains an Uncontrolled Resource Consumptio…7.5
- CVE-2022-22557PowerStore contains Plain-Text Password Storage Vulnerabilit…7.8
Are you affected by CVE-2022-22551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
