PT-2022-4923 · Dell Emc · Dell Emc Cloudlink

Published

2022-08-01

·

Updated

2022-09-07

·

CVE-2022-34379

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC CloudLink versions prior to 7.1.2
Description The issue is related to weaknesses in the authentication procedure, allowing a remote attacker with knowledge of active directory usernames to potentially gain unauthorized access to the system. This could lead to exploitation of the vulnerability, resulting in unauthorized system access.
Recommendations For versions prior to 7.1.2, update to version 7.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2022-06095
CVE-2022-34379

Affected Products

Dell Emc Cloudlink