Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks

Project Subscriptions

Vendors Products
Powerstore 1000t Subscribe
Powerstore 1200t Subscribe
Powerstore 3000t Subscribe
Powerstore 3200t Subscribe
Powerstore 5000t Subscribe
Powerstore 500t Subscribe
Powerstore 5200t Subscribe
Powerstore 7000t Subscribe
Powerstore 9000t Subscribe
Powerstore 9200t Subscribe
Powerstoreos Subscribe
Powerstoret Os Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-36693 Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell powerstoreos
CPEs cpe:2.3:o:dell:powerstoreos:-:*:*:*:*:*:*:*
Vendors & Products Dell powerstoreos
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-12-04T21:36:20.019Z

Reserved: 2023-05-09T06:02:34.291Z

Link: CVE-2023-32449

cve-icon Vulnrichment

Updated: 2024-08-02T15:18:37.306Z

cve-icon NVD

Status : Modified

Published: 2023-06-22T07:15:08.867

Modified: 2024-11-21T08:03:22.523

Link: CVE-2023-32449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses