CVE-2022-34380
Last modified
CVE-2022-34380 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability as it allows attacker to take control of the system.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Cloudlink | < 7.1.4 |
References
- https://www.dell.com/support/kbdoc/en-us/000202058/dsa-2022-210-dell-emc-cloudlink-security-update-for-multiple-security-vulnerabilitiesMitigation, Patch, Vendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000202058/dsa-2022-210-dell-emc-cloudlink-security-update-for-multiple-security-vulnerabilitiesMitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34380?
How severe is CVE-2022-34380?
How do I fix CVE-2022-34380?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34375Dell Container Storage Modules 1.2 contains a path traversal…6.5
- CVE-2022-34376 Dell PowerEdge BIOS and Dell Precision BIOS contain an im…5.5
- CVE-2022-34377 Dell PowerEdge BIOS and Dell Precision BIOS contain an Im…6.7
- CVE-2022-34378Dell PowerScale OneFS, versions 9.0.0 up to and including 9.…5.5
- CVE-2022-34379Dell EMC CloudLink 7.1.2 and all prior versions contain an A…9.8
- CVE-2022-3438Open Redirect in GitHub repository ikus060/rdiffweb prior to…6.1
- CVE-2022-34381 Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5,…9.8
- CVE-2022-34382Dell Command Update, Dell Update and Alienware Update versio…7.8
- CVE-2022-34383Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain…8.2
- CVE-2022-34384 Dell SupportAssist Client Consumer (version 3.11.1 and prio…7.8
- CVE-2022-34385 SupportAssist for Home PCs (version 3.11.4 and prior) and …5.5
- CVE-2022-34386 Dell SupportAssist for Home PCs (version 3.11.4 and prior) …5.5
Are you affected by CVE-2022-34380?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
