CVE Vulnerabilities

CVE-2022-31233

Incorrect Resource Transfer Between Spheres

Published: Aug 31, 2022 | Modified: Sep 07, 2022
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

Name Vendor Start Version End Version
Evasa_provider_virtual_appliance Dell * 9.2.3.7 (excluding)
Solutions_enabler Dell * 9.2.3.4 (excluding)
Solutions_enabler_virtual_appliance Dell * 9.2.3.4 (excluding)
Unisphere_360 Dell * 9.2.3.6 (excluding)
Unisphere_for_powermax Dell * 9.2.3.15 (excluding)
Unisphere_for_powermax_virtual_appliance Dell * 9.2.3.15 (excluding)
Vasa Dell * 9.2.3.15 (excluding)
Powermax_os Dell 5978 (including) 5978 (including)

References