« Volver al listado

CVE-2022-45103

Estado: ModificadaMedia (6.5)—

Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-45103",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-45103",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-02T16:10:27.465411Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Unisphere for PowerMax vApp",
          "versions": [
            {
              "status": "affected",
              "version": "9.2.3.x"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-01-18T15:15:11.313",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-for-powermax-dell-unisphere-for-powermax-vapp-dell-solutions-enabler-vapp-dell-unisphere-360-dell-vasa-provider-vapp-and-dell-powermax-emb-mgmt-security-update-for-multiple-vulnerabilities",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-for-powermax-dell-unisphere-for-powermax-vapp-dell-solutions-enabler-vapp-dell-unisphere-360-dell-vasa-provider-vapp-and-dell-powermax-emb-mgmt-security-update-for-multiple-vulnerabilities",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nDell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.\n\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "Las versiones 9.2.3.x de Dell Unisphere para PowerMax vApp, VASA Provider vApp y Solution Enabler vApp versión 9.2.3.x contienen una vulnerabilidad de divulgación de información. Un atacante remoto con pocos privilegios podría explotar esta vulnerabilidad, lo que llevaría a leer archivos arbitrarios en el sistema de archivos subyacente."
    }
  ],
  "lastModified": "2026-06-17T05:09:22.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:emc_solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8387C0A6-5B08-4ED3-94C9-3F6A0D2FD663",
              "versionEndExcluding": "9.2.3.6"
            },
            {
              "criteria": "cpe:2.3:a:dell:emc_unisphere_for_powermax:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90943C0A-23EE-4FF4-82FE-B095B4F7F647",
              "versionEndExcluding": "9.2.3.22"
            },
            {
              "criteria": "cpe:2.3:a:dell:emc_unisphere_for_powermax:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBCE9AB3-9796-4F15-AC46-6209E85C98BF",
              "versionEndExcluding": "10.0.0.5",
              "versionStartIncluding": "10.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:emc_unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D79BF436-665F-4D1E-963C-1EE7C87CC1E5",
              "versionEndExcluding": "9.2.3.22"
            },
            {
              "criteria": "cpe:2.3:a:dell:emc_vasa_provider_virtual_appliance:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2B03A15-20F8-4A9D-8EE5-873B0A85ED1E",
              "versionEndExcluding": "9.2.4.15"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27D9AEC0-7614-4E79-BAF7-36939780DA12",
              "versionEndExcluding": "9.2.3.6"
            },
            {
              "criteria": "cpe:2.3:a:dell:solutions_enabler:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34ECB10B-FB47-4B2D-8629-DCAD9D46E630",
              "versionEndExcluding": "10.0.0.5",
              "versionStartIncluding": "10.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dell:unisphere_360:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD8C2F65-AFDA-4B55-ABE6-CFDBA027F66A",
              "versionEndExcluding": "9.2.3.12"
            },
            {
              "criteria": "cpe:2.3:a:dell:vasa_provider:*:*:*:*:standalone:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDC05F62-AC66-4CC2-85DA-E7DFCE645FDF",
              "versionEndExcluding": "9.2.4.22"
            },
            {
              "criteria": "cpe:2.3:o:dell:powermax_os:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "053A6C03-0833-4F96-9D5F-466A5B9DB84B"
            },
            {
              "criteria": "cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43696C46-48E8-43E4-9387-77CE1B2BD401"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}