CVE-2022-34397

MEDIUM

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp <= 10.0.0.5 - Incorrect Authorization

Title source: llm
STIX 2.1

Description

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.

Scores

CVSS v3 6.9
EPSS 0.0006
EPSS Percentile 19.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (5)
dell/evasa_provider_virtual_appliance < 9.2.4.15
dell/solutions_enabler_virtual_appliance < 9.2.3.6
dell/solutions_enabler_virtual_appliance < 9.2.4.26
dell/unisphere_for_powermax_virtual_appliance < 9.2.3.22
dell/unisphere_for_powermax_virtual_appliance < 9.2.4.26
Published Feb 13, 2023
Tracked Since Feb 18, 2026