Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
Link | Tags |
---|---|
https://www.dell.com/support/kbdoc/000194640 | patch vendor advisory |