CVE-2022-34367Cross-Site Request Forgery in Dell Data Protection Central

Severity
8.8HIGHNVD
CNA5.4
EPSS
0.2%
top 55.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 21
Latest updateJul 22

Description

Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, leading to processing of unintended server operations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5dell/data_protection_centralunspecified19.7

🔴Vulnerability Details

2
GHSA
GHSA-w26q-54h4-q58c: Dell EMC Data Protection Central versions 192022-07-22
CVEList
CVE-2022-34367: Dell EMC Data Protection Central versions 192022-07-20
CVE-2022-34367 — Cross-Site Request Forgery in Dell | cvebase