7.8

CVE-2023-32449

Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 500t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 1000t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 1200t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 3200t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 3000t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 5200t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 5000t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 7000t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 9000t Version -
Dell ≫ Powerstoret Os Version < 3.5.0.0-2050321
   Dell ≫ Powerstore 9200t Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EMC 7.2 0.6 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://www.dell.com/support/kbdoc/en-us/000215171/dsa-2023-173-dell-powerstore-family-security-update-for-multiple-vulnerabilities
Patch
Vendor Advisory