CVE-2022-26868
Summary
| CVE | CVE-2022-26868 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-02 21:15:00 UTC |
| Updated | 2022-06-13 17:14:00 UTC |
| Description | Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover by an attacker. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Dell | Powerstoreos | All | All | All | All |
| Hardware | Dell | Powerstore T | - | All | All | All |
| Hardware | Dell | Powerstore X | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2022-014: Dell EMC PowerStore Family Security Update for Multiple Vulnerabilities | Dell US | CONFIRM | www.dell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.