Vulnerability Details CVE-2022-33923
Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.2%
CVSS Severity
CVSS v3 Score 6.4
Products affected by CVE-2022-33923
-
cpe:2.3:h:dell:emc_powerstore_1200t:-
-
cpe:2.3:h:dell:emc_powerstore_3200t:-
-
cpe:2.3:h:dell:emc_powerstore_500t:-
-
cpe:2.3:h:dell:emc_powerstore_5200t:-
-
cpe:2.3:h:dell:emc_powerstore_9200t:-
-
cpe:2.3:o:dell:emc_powerstore_1200t_firmware:*
-
cpe:2.3:o:dell:emc_powerstore_3200t_firmware:*
-
cpe:2.3:o:dell:emc_powerstore_500t_firmware:*
-
cpe:2.3:o:dell:emc_powerstore_5200t_firmware:*
-
cpe:2.3:o:dell:emc_powerstore_9200t_firmware:*