DSA-2022-207: Dell CloudLink Security Update for an AD Users Login Without Password Vulnerability
Summary: Dell CloudLink remediation is available for AD users login without password that may be exploited by malicious users to compromise the affected system.
Impact
Critical
Details
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2022-34379 |
Dell CloudLink 7.1.2 and all earlier versions contain an Authentication Bypass Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink web console. This is critical severity vulnerability as it allows attacker to take control of the system. |
9.1 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2022-34379 |
Dell CloudLink 7.1.2 and all earlier versions contain an Authentication Bypass Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink web console. This is critical severity vulnerability as it allows attacker to take control of the system. |
9.1 |
Affected Products & Remediation
| Product |
Affected Versions |
Updated Version |
Link to Update |
| Dell CloudLink |
Versions before 7.1.3 |
7.1.3 |
| Product |
Affected Versions |
Updated Version |
Link to Update |
| Dell CloudLink |
Versions before 7.1.3 |
7.1.3 |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2022-08-01 |
Initial Release |