Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Solutions_enabler | Dell | * | 9.1.0.15 (excluding) |
Solutions_enabler | Dell | 9.2.0 (including) | 9.2.1.6 (excluding) |
Solutions_enabler_virtual_appliance | Dell | * | 9.1.0.15 (excluding) |
Solutions_enabler_virtual_appliance | Dell | 9.2.0 (including) | 9.2.1.1 (excluding) |
Unisphere_for_powermax | Dell | * | 9.1.0.26 (excluding) |
Unisphere_for_powermax | Dell | 9.2.1.0 (including) | 9.2.1.6 (including) |
Unisphere_for_powermax_virtual_appliance | Dell | * | 9.1.0.26 (excluding) |
Unisphere_for_powermax_virtual_appliance | Dell | 9.2.1.0 (including) | 9.2.1.6 (excluding) |
Powermax_os | Dell | 5978 (including) | 5978 (including) |