CVE-2022-31231: High severity Dell EMC ECS vulnerability
Published May 22, 2026
·Updated
Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.
Affected Software
3 affected components
Dell EMC ECS=3.5, =3.6
Dell Elastic Cloud Storage<3.5.1.7
Dell Elastic Cloud Storage>=3.6.0.0<3.6.2.4
Event History
May 22, 2026
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-31231?
The severity of CVE-2022-31231 is rated as medium, with a score of 5.9.
2
How do I fix CVE-2022-31231?
To fix CVE-2022-31231, upgrade to a patched version of Dell EMC ECS beyond 3.6.
3
What type of vulnerability is CVE-2022-31231?
CVE-2022-31231 is classified as an Improper Access Control vulnerability in the Identity and Access Management module.
4
Who is affected by CVE-2022-31231?
CVE-2022-31231 affects users of Dell ECS versions 3.5 and 3.6.
5
What could an attacker do with CVE-2022-31231?
An attacker could potentially exploit CVE-2022-31231 to gain unauthorized read access to sensitive data.