Vulnerability Description
Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Unity Operating Environment | < 5.2.0.0.5.173 |
| Dell | Unity Xt Operating Environment | < 5.2.0.0.5.173 |
| Dell | Unityvsa Operating Environment | < 5.2.0.0.5.173 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000199050Vendor Advisory
- https://www.dell.com/support/kbdoc/000199050Vendor Advisory
FAQ
What is CVE-2022-29084?
CVE-2022-29084 is a vulnerability with a CVSS score of 8.1 (HIGH). Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit...
How severe is CVE-2022-29084?
CVE-2022-29084 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29084?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Unity Operating Environment, Dell Unity Xt Operating Environment, Dell Unityvsa Operating Environment.