CVE-2022-22555: OS Command Injection
Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22555?
CVE-2022-22555 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2022-22555?
To fix CVE-2022-22555, you should update the Dell EMC PowerStore firmware to versions beyond 3.0.0.0-1732745.
What types of systems are affected by CVE-2022-22555?
CVE-2022-22555 affects multiple models of Dell EMC PowerStore firmware, including 500T, 1200T, 3200T, 5200T, and 9200T.
Can CVE-2022-22555 be exploited remotely?
No, CVE-2022-22555 requires local authentication to exploit the vulnerability.
What impacts does CVE-2022-22555 have if exploited?
Exploitation of CVE-2022-22555 could allow an attacker to execute arbitrary operating system commands with the privileges of the vulnerable application.