CVE-2022-45103

MEDIUM

Dell Unisphere for PowerMax vApp 9.2.3.x - Unauthenticated Arbitrary File Read

Title source: llm
STIX 2.1

Description

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 47.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (9)
dell/emc_solutions_enabler_virtual_appliance < 9.2.3.6
dell/emc_unisphere_for_powermax < 9.2.3.22
dell/emc_unisphere_for_powermax_virtual_appliance < 9.2.3.22
dell/emc_vasa_provider_virtual_appliance < 9.2.4.15
dell/powermax_os
dell/powermax_os 5978
dell/solutions_enabler < 9.2.3.6
dell/unisphere_360 < 9.2.3.12
dell/vasa_provider < 9.2.4.22
Published Jan 18, 2023
Tracked Since Feb 18, 2026