CVE-2023-32449

Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:03

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000215171/dsa-2023-173-dell-powerstore-family-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000215171/dsa-2023-173-dell-powerstore-family-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.2

28 Jun 2023, 15:21

Type Values Removed Values Added
First Time Dell powerstore 5000t
Dell powerstore 9200t
Dell powerstore 1200t
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstoret Os
Dell powerstore 500t
Dell powerstore 3000t
Dell powerstore 1000t
Dell powerstore 9000t
Dell powerstore 3200t
Dell
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*
References (MISC) https://www.dell.com/support/kbdoc/en-us/000215171/dsa-2023-173-dell-powerstore-family-security-update-for-multiple-vulnerabilities - (MISC) https://www.dell.com/support/kbdoc/en-us/000215171/dsa-2023-173-dell-powerstore-family-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory

22 Jun 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-22 07:15

Updated : 2024-11-21 08:03


NVD link : CVE-2023-32449

Mitre link : CVE-2023-32449

CVE.ORG link : CVE-2023-32449


JSON object : View

Products Affected

dell

  • powerstore_9000t
  • powerstore_1000t
  • powerstore_500t
  • powerstore_1200t
  • powerstore_9200t
  • powerstore_5200t
  • powerstoret_os
  • powerstore_3200t
  • powerstore_5000t
  • powerstore_3000t
  • powerstore_7000t
CWE
CWE-347

Improper Verification of Cryptographic Signature