Impact
High
Gegevens
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
CVE-2022-29089 |
Networking OS10, versions before October 2021 with SmartFabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker may potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and access the REST API with admin privileges. |
6.4 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
CVE-2022-34424 |
Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that may potentially allow an attacker to cause a system crash by running particular security scans. |
7.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
CVE-2022-29089 |
Networking OS10, versions before October 2021 with SmartFabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker may potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and access the REST API with admin privileges. |
6.4 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
CVE-2022-34424 |
Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that may potentially allow an attacker to cause a system crash by running particular security scans. |
7.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Dell Technologies raadt aan dat alle klanten rekening houden met zowel de basisscore van CVSS als alle relevante tijdelijke en omgevingsscores die gevolgen kunnen hebben voor de mogelijke ernst van de specifieke beveiligingsproblemen.
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Note: The table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Revisiegeschiedenis
Revision | Date | Description |
1.0 | 2022-09-01 | Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Getroffen producten
SmartFabric OS10 Software
Producten
Product Security Information