CVE-2022-32498

MEDIUM

Dell Powerstore Command Line Interface - Uncontrolled Search Path

Title source: rule

Description

Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 17.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L

Classification

CWE
CWE-427
Status published

Affected Products (1)

dell/powerstore_command_line_interface < 3.0.0.0-1732745

Timeline

Published Jul 21, 2022
Tracked Since Feb 18, 2026