PT-2022-19403 · Dell · Dell Unity+3

Published

2022-06-02

·

Updated

2022-06-13

·

CVE-2022-29084

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173
Description The issue allows a remote unauthenticated attacker to potentially brute-force passwords and gain access to the system as the victim due to the lack of restriction on excessive authentication attempts in the Unisphere GUI. Account takeover is possible if weak passwords are used by users.
Recommendations For versions before 5.2.0.0.5.173, update to version 5.2.0.0.5.173 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication controls or monitoring to detect and prevent brute-force attacks. Restrict access to the Unisphere GUI to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29084

Affected Products

Dell Unity
Dell Unity Xt
Dell Unityvsa
Unisphere Gui