First published: Fri Feb 10 2023(Updated: )
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker with administrative privileges could potentially exploit the issue and execute commands on the system as the root user.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerPath | =3.0 | |
Dell PowerPath | =3.1 | |
Dell PowerPath | =3.2 | |
Dell PowerPath | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34447 is a vulnerability in PowerPath Management Appliance versions 3.3 & 3.2*, 3.1 & 3.0*, which allows an authenticated remote attacker with admin privileges to execute commands as the root user.
CVE-2022-34447 has a severity rating of 7.2, which is considered high.
PowerPath Management Appliance versions 3.3, 3.2*, 3.1, and 3.0* are affected by CVE-2022-34447.
An attacker with administrative privileges can exploit CVE-2022-34447 by injecting OS commands to execute arbitrary commands on the system.
Dell has released a fix for CVE-2022-34447. It is recommended to update to the latest version of PowerPath Management Appliance to mitigate the vulnerability.