PT-2022-18114 · Dell · Powerstore Sw

Published

2022-06-02

·

Updated

2022-06-13

·

CVE-2022-26867

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PowerStore SW version 2.1.1.0
Description The issue allows a malicious, authenticated user to inject payloads into CSV or XLSX files exported from PowerStore SW. These payloads might be interpreted as formulas by the corresponding spreadsheet application, potentially leading to malicious actions. The data is taken as is, without any validation or sanitization.
Recommendations For PowerStore SW version 2.1.1.0, consider validating and sanitizing the data before exporting it to CSV or XLSX files to prevent malicious payload injection. As a temporary workaround, restrict the use of the export feature to trusted users only, and ensure that the spreadsheet applications used to open these files are configured to warn users about potential formula injections.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26867

Affected Products

Powerstore Sw