First published: Mon Feb 13 2023(Updated: )
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Evasa Provider Virtual Appliance | <9.2.4.15 | |
Dell Solutions Enabler Virtual Appliance | <9.2.3.6 | |
Dell Solutions Enabler Virtual Appliance | <9.2.4.26 | |
Dell Unisphere For Powermax Virtual Appliance | <9.2.3.22 | |
Dell Unisphere For Powermax Virtual Appliance | <9.2.4.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34397 is a vulnerability in Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below that allows unauthorized actions to be performed.
CVE-2022-34397 has a severity score of 5.7, which is classified as medium.
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below are affected by CVE-2022-34397.
To fix CVE-2022-34397, it is recommended to update Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp to a version above 10.0.0.5.
More information about CVE-2022-34397 can be found in the Dell security advisory at https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-for-powermax-dell-unisphere-for-powermax-vapp-dell-solutions-enabler-vapp-dell-unisphere-360-dell-vasa-provider-vapp-and-dell-powermax-emb-mgmt-security-update-for-multiple-vulnerabilities.