PT-2022-5194 · Dell · Cloud Mobility For Dell Emc Storage
CVE-2022-34434
·
Published
2022-06-23
·
Updated
2023-06-29
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cloud Mobility for Dell Storage versions 1.3.0 and earlier
Description
The issue is related to improper authorization in the system, which can allow an attacker to access protected information. A threat actor with root-level access to either the vApp or containerized versions of Cloud Mobility may exploit this issue, potentially leading to the modification or deletion of tables required for core functionalities. This could compromise the integrity and availability of the normal functionality of the Cloud Mobility application.
Recommendations
For Cloud Mobility for Dell Storage versions 1.3.0 and earlier, consider restricting root-level access to the vApp or containerized versions to minimize the risk of exploitation. As a temporary workaround, limit modifications to the Postgres database tables that are crucial for the core functionalities of Cloud Mobility until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Mobility For Dell Emc Storage