CVE-2022-34453

Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:xtremio_x2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:xtremio_x2:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:09

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000204809/dsa-2022-290-dell-xtremio-x2-security-advisory-for-xms-gui?lang=en - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000204809/dsa-2022-290-dell-xtremio-x2-security-advisory-for-xms-gui?lang=en - Vendor Advisory
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 7.6

08 Aug 2023, 19:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CPE cpe:2.3:o:dell:xtremio_x2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:xtremio_x2:-:*:*:*:*:*:*:*
First Time Dell
Dell xtremio X2
Dell xtremio X2 Firmware
References (MISC) https://www.dell.com/support/kbdoc/en-us/000204809/dsa-2022-290-dell-xtremio-x2-security-advisory-for-xms-gui?lang=en - (MISC) https://www.dell.com/support/kbdoc/en-us/000204809/dsa-2022-290-dell-xtremio-x2-security-advisory-for-xms-gui?lang=en - Vendor Advisory
CWE CWE-284 NVD-CWE-Other

03 Aug 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-03 13:15

Updated : 2024-11-21 07:09


NVD link : CVE-2022-34453

Mitre link : CVE-2022-34453

CVE.ORG link : CVE-2022-34453


JSON object : View

Products Affected

dell

  • xtremio_x2
  • xtremio_x2_firmware
CWE
CWE-284

Improper Access Control

NVD-CWE-Other