« Volver al listado

CVE-2022-33923

Estado: ModificadaAlta (7.8)—

Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-33923",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "PowerStore",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.0.0.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-21T04:15:12.987",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/000201283",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/000201283",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker."
    },
    {
      "lang": "es",
      "value": "Dell PowerStore, versiones anteriores a 3.0.0.0, contiene una vulnerabilidad de inyección de comandos del Sistema Operativo en el entorno PowerStore T. Un atacante autenticado localmente podría potencialmente explotar esta vulnerabilidad, conllevando a una ejecución de un comando de SO arbitrario en el SO subyacente de PowerStore. La explotación puede conllevar a una toma de control del sistema por parte de un atacante"
    }
  ],
  "lastModified": "2026-06-17T04:49:29.813",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerstore_500t_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E7999B2-9790-43D7-A231-0206A36AEC3C",
              "versionEndExcluding": "3.0.0.0-1732745"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerstore_500t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2F396420-8007-401C-985E-436C227B42A9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerstore_1200t_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "761D6F6E-D4BF-4B83-8EED-19DF784BB223",
              "versionEndExcluding": "3.0.0.0-1732745"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerstore_1200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FB705779-4464-447D-BFB6-63073FFC026F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerstore_3200t_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "191F6EDA-88C2-4C18-89B5-0D6200FD15CE",
              "versionEndExcluding": "3.0.0.0-1732745"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerstore_3200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C19A09B3-64C4-4FBF-91DA-782E117FD0F2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerstore_5200t_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "428A51ED-C8B5-4FC0-84E2-D74D2B3F7447",
              "versionEndExcluding": "3.0.0.0-1732745"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerstore_5200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E67E33BD-8D23-4B30-83A6-B2105ACF5EFC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:emc_powerstore_9200t_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BD1DB6E-CB42-4A67-98D6-23F0E88BDEE5",
              "versionEndExcluding": "3.0.0.0-1732745"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerstore_9200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "20FD2CBE-D0CE-442C-B961-E8DE951A4645"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}