CVE-2022-34434
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to either the vApp or containerized versions of Cloud Mobility may potentially exploit this vulnerability, leading to the modification or deletion of tables that are required for many of the core functionalities of Cloud Mobility. Exploitation may lead to the compromise of integrity and availability of the normal functionality of the Cloud Mobility application.
Cloud Mobility para Dell Storage versiones 1.3.0 y anteriores, contiene una vulnerabilidad de control de acceso inapropiado en la base de datos Postgres. Un actor de la amenaza con acceso a nivel root a la vApp o a las versiones en contenedor de Cloud Mobility podría explotar esta vulnerabilidad, conllevando a una modificación o eliminación de tablas necesarias para muchas de las funcionalidades principales de Cloud Mobility. Una explotación puede conllevar a un compromiso de la integridad y la disponibilidad de la funcionalidad normal de la aplicación Cloud Mobility
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-23 CVE Reserved
- 2022-10-11 CVE Published
- 2024-04-07 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/kbdoc/en-vc/000203434/dsa-2022-264-cloud-mobility-for-dell-storage-security-update-for-an-insecure-database-vulnerability | 2023-06-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Cloud Mobility For Dell Emc Storage Search vendor "Dell" for product "Cloud Mobility For Dell Emc Storage" | < 1.3.1 Search vendor "Dell" for product "Cloud Mobility For Dell Emc Storage" and version " < 1.3.1" | - |
Affected
|