Lucene search

K
cveDellCVE-2022-34374
HistoryAug 30, 2022 - 9:15 p.m.

CVE-2022-34374

2022-08-3021:15:08
CWE-78
dell
web.nvd.nist.gov
32
3
cve-2022-34374
dell
container storage modules
os command injection
vulnerability
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

57.0%

Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.

Affected configurations

Nvd
Vulners
Node
dellcontainer_storage_modulesRange<1.3.0
VendorProductVersionCPE
dellcontainer_storage_modules*cpe:2.3:a:dell:container_storage_modules:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Dell Container Storage Modules",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "1.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

57.0%

Related for CVE-2022-34374