PT-2022-5194 · Dell · Cloud Mobility For Dell Emc Storage

CVE-2022-34434

·

Published

2022-06-23

·

Updated

2023-06-29

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cloud Mobility for Dell Storage versions 1.3.0 and earlier
Description The issue is related to improper authorization in the system, which can allow an attacker to access protected information. A threat actor with root-level access to either the vApp or containerized versions of Cloud Mobility may exploit this issue, potentially leading to the modification or deletion of tables required for core functionalities. This could compromise the integrity and availability of the normal functionality of the Cloud Mobility application.
Recommendations For Cloud Mobility for Dell Storage versions 1.3.0 and earlier, consider restricting root-level access to the vApp or containerized versions to minimize the risk of exploitation. As a temporary workaround, limit modifications to the Postgres database tables that are crucial for the core functionalities of Cloud Mobility until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06451
CVE-2022-34434

Affected Products

Cloud Mobility For Dell Emc Storage