CVE-2022-34446
Last modified
CVE-2022-34446 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration. . EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Powerpath Management Appliance | 3.2 |
| Dell | Powerpath Management Appliance | 3.3 |
References
- https://www.dell.com/support/kbdoc/000205404Vendor Advisory
- https://www.dell.com/support/kbdoc/000205404Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34446?
How severe is CVE-2022-34446?
How do I fix CVE-2022-34446?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34440Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, con…9.8
- CVE-2022-34441 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, co…9.8
- CVE-2022-34442 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, co…9.8
- CVE-2022-34443 Dell Rugged Control Center, versions prior to 4.5, contain …7.8
- CVE-2022-34444 Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x con…7.5
- CVE-2022-34445 Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain…4.4
- CVE-2022-34447 PowerPath Management Appliance with versions 3.3 & 3.2*, 3.…7.2
- CVE-2022-34448 PowerPath Management Appliance with versions 3.3 & 3.2*, 3.…8.8
- CVE-2022-34449 PowerPath Management Appliance with versions 3.3 & 3.2* con…6
- CVE-2022-3445Use after free in Skia in Google Chrome prior to 106.0.5249.…8.8
- CVE-2022-34450 PowerPath Management Appliance with version 3.3 contains Pr…6.7
- CVE-2022-34451 PowerPath Management Appliance with versions 3.3 & 3.2*, 3.…4.8
Are you affected by CVE-2022-34446?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
