CVE-2022-22553

HIGH

Dell EMC AppSync 3.9-4.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.dell.com/support/kbdoc/000195377

Scores

CVSS v3 8.1
EPSS 0.0046
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-307
Status published
Products (1)
dell/emc_appsync < 4.4.0.0
Published Jan 21, 2022
Tracked Since Feb 18, 2026