CVE-2022-34453

Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:xtremio_x2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:xtremio_x2:-:*:*:*:*:*:*:*

History

08 Aug 2023, 19:14

Type Values Removed Values Added
CPE cpe:2.3:o:dell:xtremio_x2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:xtremio_x2:-:*:*:*:*:*:*:*
First Time Dell xtremio X2 Firmware
Dell
Dell xtremio X2
References (MISC) https://www.dell.com/support/kbdoc/en-us/000204809/dsa-2022-290-dell-xtremio-x2-security-advisory-for-xms-gui?lang=en - (MISC) https://www.dell.com/support/kbdoc/en-us/000204809/dsa-2022-290-dell-xtremio-x2-security-advisory-for-xms-gui?lang=en - Vendor Advisory
CWE CWE-284 NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

03 Aug 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-03 13:15

Updated : 2023-12-10 15:14


NVD link : CVE-2022-34453

Mitre link : CVE-2022-34453

CVE.ORG link : CVE-2022-34453


JSON object : View

Products Affected

dell

  • xtremio_x2
  • xtremio_x2_firmware
CWE
NVD-CWE-Other CWE-284

Improper Access Control