CVE-2022-34437: OS Command Injection
Published Oct 21, 2022
·Updated
Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This impacts compliance mode clusters.
Affected Software
3 affected components
Dell EMC PowerScale OneFS>=9.1.0.0<=9.1.0.21
Dell EMC PowerScale OneFS>=9.2.1.0<=9.2.1.15
Dell EMC PowerScale OneFS>=9.3.0.0<=9.3.0.7
Remediation
Event History
Oct 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-34437?
CVE-2022-34437 is an OS command injection vulnerability in Dell PowerScale OneFS versions 8.2.2-9.3.0.
2
How does CVE-2022-34437 impact Dell PowerScale OneFS?
CVE-2022-34437 allows a privileged local malicious user to exploit this vulnerability and potentially compromise the entire system.
3
Which software versions are affected by CVE-2022-34437?
Dell PowerScale OneFS versions 8.2.2-9.3.0 are affected by CVE-2022-34437.
4
What is the severity of CVE-2022-34437?
CVE-2022-34437 has a severity of medium, with a CVSS score of 6.7.
5
How can I fix CVE-2022-34437?
To fix CVE-2022-34437, you need to apply the security update provided by Dell EMC PowerScale OneFS.