Improper Authentication Management in Dell EMC PowerStore Manager
CVE-2022-31234

8.1HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
21 July 2022

Summary

Dell EMC PowerStore's Manager GUI exhibits an improper restriction of excessive authentication attempts, which could be exploited by a remote unauthenticated attacker. This vulnerability allows attackers to perform brute-force password attacks, potentially leading to account compromises, especially if users have weak passwords. It is crucial for users to adopt strong password policies to mitigate the risk of unauthorized access.

Affected Version(s)

PowerStore < unspecified

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.