CVE-2022-26857: Critical severity dell openmanage vulnerability
Published May 26, 2022
·Updated
Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.
Affected Software
1 affected component
Dell OpenManage Enterprise<3.8.4
Event History
May 26, 2022
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-26857?
CVE-2022-26857 is considered a high severity vulnerability due to its potential impact on improper authorization.
2
How do I fix CVE-2022-26857?
To fix CVE-2022-26857, upgrade Dell OpenManage Enterprise to version 3.8.4 or later.
3
Who is affected by CVE-2022-26857?
CVE-2022-26857 affects Dell OpenManage Enterprise versions 3.8.3 and prior.
4
Can a low-privileged user exploit CVE-2022-26857?
Yes, a remote authenticated malicious user with low privileges can exploit CVE-2022-26857.
5
What kind of actions can be performed due to CVE-2022-26857?
CVE-2022-26857 allows unauthorized actions by bypassing blocked functionalities.