CVE-2022-32498
MEDIUMDell Powerstore Command Line Interface - Uncontrolled Search Path
Title source: ruleDescription
Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure.
Scores
CVSS v3
5.5
EPSS
0.0006
EPSS Percentile
17.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L
Classification
CWE
CWE-427
Status
published
Affected Products (1)
dell/powerstore_command_line_interface
< 3.0.0.0-1732745
Timeline
Published
Jul 21, 2022
Tracked Since
Feb 18, 2026