CVE-2022-34397
Last modified
CVE-2022-34397 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized. . EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Evasa Provider Virtual Appliance | < 9.2.4.15 |
| Dell | Solutions Enabler Virtual Appliance | < 9.2.3.6 |
| Dell | Solutions Enabler Virtual Appliance | < 9.2.4.26 |
| Dell | Unisphere For Powermax Virtual Appliance | < 9.2.3.22 |
| Dell | Unisphere For Powermax Virtual Appliance | < 9.2.4.26 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34397?
How severe is CVE-2022-34397?
How do I fix CVE-2022-34397?
Are you affected by CVE-2022-34397?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
