CVE-2022-22553: Critical severity Dell EMC AppSync vulnerability
Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22553?
CVE-2022-22553 is classified as a high severity vulnerability due to its potential for password brute-forcing and account takeover.
How do I fix CVE-2022-22553?
To fix CVE-2022-22553, upgrade Dell EMC AppSync to version 4.4.0.0 or later.
Who is affected by CVE-2022-22553?
Users of Dell EMC AppSync versions 3.9 to 4.3 are affected by CVE-2022-22553.
Can CVE-2022-22553 be exploited remotely?
Yes, CVE-2022-22553 can be exploited remotely by an adjacent unauthenticated attacker.
What type of attack does CVE-2022-22553 facilitate?
CVE-2022-22553 facilitates a password brute-forcing attack that could lead to account takeover.