Command Injection Vulnerability in Dell EMC PowerStore Products
CVE-2022-26868

6.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
2 June 2022

Summary

Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x suffer from a command injection vulnerability that enables an authenticated attacker to execute arbitrary operating system commands on the underlying system. This flaw can lead to potential system takeover by leveraging the application's privileges during exploitation.

Affected Version(s)

PowerStore < unspecified

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.