Improper Authentication Management in Dell EMC PowerStore Manager
CVE-2022-31234
8.1HIGH
Summary
Dell EMC PowerStore's Manager GUI exhibits an improper restriction of excessive authentication attempts, which could be exploited by a remote unauthenticated attacker. This vulnerability allows attackers to perform brute-force password attacks, potentially leading to account compromises, especially if users have weak passwords. It is crucial for users to adopt strong password policies to mitigate the risk of unauthorized access.
Affected Version(s)
PowerStore < unspecified
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved