Vulnerability Description
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Powerstoreos | < 2.1.1.0 |
| Dell | Powerstore T | - |
| Dell | Powerstore X | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000196367Vendor Advisory
- https://www.dell.com/support/kbdoc/000196367Vendor Advisory
FAQ
What is CVE-2022-26867?
CVE-2022-26867 is a vulnerability with a CVSS score of 5.9 (MEDIUM). PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to...
How severe is CVE-2022-26867?
CVE-2022-26867 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26867?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Powerstoreos, Dell Powerstore T, Dell Powerstore X.