CVE-2022-34446

HIGH

Dell PowerPath Management Appliance 3.2-3.3 - Authenticated Authorization Bypass

Title source: llm
STIX 2.1

Description

PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://www.dell.com/support/kbdoc/000205404

Scores

CVSS v3 8.8
EPSS 0.0026
EPSS Percentile 49.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (2)
dell/powerpath_management_appliance 3.2
dell/powerpath_management_appliance 3.3
Published Feb 11, 2023
Tracked Since Feb 18, 2026