// For flags

CVE-2022-32498

 

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit this vulnerability to execute arbitrary code, escalate privileges, and bypass software allow list solutions, leading to system takeover or IP exposure.

Dell EMC PowerStore, versiones anteriores a v3.0.0.0, contienen una vulnerabilidad de secuestro de DLL en PSTCLI. Un atacante local puede explotar potencialmente esta vulnerabilidad para ejecutar código arbitrario, escalar privilegios y omitir las soluciones de la lista de permisos del software, conllevando la toma de control del sistema o la exposición de la IP

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-06-06 CVE Reserved
  • 2022-07-20 CVE Published
  • 2023-12-31 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dell
Search vendor "Dell"
Powerstore Command Line Interface
Search vendor "Dell" for product "Powerstore Command Line Interface"
< 3.0.0.0-1732745
Search vendor "Dell" for product "Powerstore Command Line Interface" and version " < 3.0.0.0-1732745"
linux
Affected