Use of a broken or risky cryptographic algorithm in Dell EMC Unity Operating Environment (OE) - CVE-2022-22564

 

Use of a broken or risky cryptographic algorithm in Dell EMC Unity Operating Environment (OE) - CVE-2022-22564

Published: August 7, 2023


Vulnerability identifier: #VU79009
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22564
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to Dell EMC Unity using broken cryptographic algorithm. A remote attacker can exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.


Affected software

Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)

How to mitigate CVE-2022-22564

Install updates from vendor's website.

Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173

External References

Related Security Bulletins