#VU79011 Improper Restriction of Excessive Authentication Attempts in Dell products - CVE-2022-29084
Published: August 7, 2023
Vulnerability identifier: #VU79011
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-29084
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Software vendor:
Dell
Dell
Description
The vulnerability allows a remote attacker to gain access to the system.
The vulnerability exists due to Dell Unity, Dell UnityVSA, and Dell Unity XT do not restrict excessive authentication attempts in Unisphere GUI. A remote attacker can exploit this vulnerability to brute-force passwords and gain access to the system.
Remediation
Install updates from vendor's website.