MEDIUM
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability
Published Jan 18, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.74%
Description
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.
Affected products
-
- Version 9.2.3.xStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dell | Unisphere for PowerMax vApp | unaffected |
|
OR
- < 9.2.3.6
- < 9.2.3.22
- ≥ 10.0.0.0 · < 10.0.0.5
- < 9.2.3.22
- < 9.2.4.15
- < 9.2.3.6
- ≥ 10.0.0.0 · < 10.0.0.5
- < 9.2.3.12
- < 9.2.4.22
- n/a
- 5978
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-48024 Advisory
- https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-for-powermax-dell-unisphere-for-powermax-vapp-dell-solutions-enabler-vapp-dell-unisphere-360-dell-vasa-provider-vapp-and-dell-powermax-emb-mgmt-security-update-for-multiple-vulnerabilities vendor-advisoryPatchVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Jan 18, 2023
Updated Apr 3, 2025
Reserved Nov 9, 2022
Link CVE-2022-45103
CISA Vulnrichment
Updated Apr 2, 2025
ENISA EUVD
EUVD-2022-48024 Assigner dell
Published Jan 18, 2023
Updated Apr 3, 2025
Exploited since n/a
Link EUVD-2022-48024