Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-51532
Disclosure Date: December 19, 2024 (last updated January 30, 2025)
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
0
Attacker Value
Unknown
CVE-2023-32478
Disclosure Date: July 21, 2023 (last updated October 08, 2023)
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2022-26869
Disclosure Date: April 19, 2022 (last updated October 07, 2023)
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-22557
Disclosure Date: April 19, 2022 (last updated October 07, 2023)
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
0
Attacker Value
Unknown
CVE-2022-26870
Disclosure Date: April 19, 2022 (last updated October 08, 2023)
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.
0
Attacker Value
Unknown
CVE-2022-22556
Disclosure Date: April 19, 2022 (last updated October 07, 2023)
Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service.
0
Attacker Value
Unknown
CVE-2022-26866
Disclosure Date: April 19, 2022 (last updated October 07, 2023)
Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
0
Attacker Value
Unknown
CVE-2022-26867
Disclosure Date: April 19, 2022 (last updated October 07, 2023)
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.
0
Attacker Value
Unknown
CVE-2022-26868
Disclosure Date: April 19, 2022 (last updated October 07, 2023)
Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover by an attacker.
0