Improper Restriction of Excessive Authentication Attempts in Dell products - CVE-2022-29084

 

Improper Restriction of Excessive Authentication Attempts in Dell products - CVE-2022-29084

Published: August 7, 2023


Vulnerability identifier: #VU79011
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29084
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to the system.

The vulnerability exists due to Dell Unity, Dell UnityVSA, and Dell Unity XT do not restrict excessive authentication attempts in Unisphere GUI. A remote attacker can exploit this vulnerability to brute-force passwords and gain access to the system.


Affected software

Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)

How to mitigate CVE-2022-29084

Install updates from vendor's website.

Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173

External References

Related Security Bulletins