Vulnerability Description
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Evasa Provider Virtual Appliance | < 9.2.4.15 |
| Dell | Solutions Enabler Virtual Appliance | < 9.2.3.6 |
| Dell | Unisphere For Powermax Virtual Appliance | < 9.2.3.22 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-fPatchVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000207177/dsa-2022-340-dell-unisphere-fPatchVendor Advisory
FAQ
What is CVE-2022-34397?
CVE-2022-34397 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which t...
How severe is CVE-2022-34397?
CVE-2022-34397 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-34397?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Evasa Provider Virtual Appliance, Dell Solutions Enabler Virtual Appliance, Dell Unisphere For Powermax Virtual Appliance.