Lucene search

K
cveDellCVE-2022-26857
HistoryMay 26, 2022 - 4:15 p.m.

CVE-2022-26857

2022-05-2616:15:08
CWE-285
dell
web.nvd.nist.gov
40
4
cve-2022-26857
dell
openmanage enterprise
improper authorization
vulnerability
nvd
security
bypass
unauthorized actions
remote authenticated
low privileges

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.003

Percentile

66.2%

Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.

Affected configurations

Nvd
Vulners
Node
dellopenmanage_enterpriseRange<3.8.4
VendorProductVersionCPE
dellopenmanage_enterprise*cpe:2.3:a:dell:openmanage_enterprise:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "OpenManage Enterprise",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "3.8.4",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.003

Percentile

66.2%

Related for CVE-2022-26857