CVE-2022-31233: High severity Dell Evasa Provider Virtual Appliance vulnerability
Published Aug 31, 2022
·Updated
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.
Affected Software
8 affected components
Dell Evasa Provider Virtual Appliance<9.2.3.7
Dell Solutions Enabler<9.2.3.4
Dell Solutions Enabler Virtual Appliance<9.2.3.4
Dell Unisphere 360<9.2.3.6
Dell Unisphere for PowerMax<9.2.3.15
Dell Unisphere For Powermax Virtual Appliance<9.2.3.15
Dell Vasa<9.2.3.15
Dell PowerMax OS=5978
Remediation
Patch Available
Event History
Aug 31, 2022
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-31233.
2
What is the severity of CVE-2022-31233?
The severity of CVE-2022-31233 is high.
3
Which versions of Unisphere for PowerMax are affected by CVE-2022-31233?
Versions of Unisphere for PowerMax before 9.2.3.15 are affected by CVE-2022-31233.
4
What is the impact of CVE-2022-31233?
CVE-2022-31233 allows an adjacent malicious user to escalate their privileges and access functionalities they do not have access to.
5
How do I fix CVE-2022-31233?
To fix CVE-2022-31233, update Unisphere for PowerMax to version 9.2.3.15 or later.