PT-2022-22151 · Dell · Dell Container Storage Modules

Published

2022-08-30

·

Updated

2022-09-02

·

CVE-2022-34374

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Container Storage Modules version 1.2
Description The issue is related to an OS command injection in the goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this, leading to the execution of arbitrary OS commands on the affected system.
Recommendations For Dell Container Storage Modules version 1.2, consider restricting access to the goiscsi and gobrick libraries until a patch is available. As a temporary workaround, limit the privileges of remote authenticated users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-34374

Affected Products

Dell Container Storage Modules