Junglewise Threat Intelligence

CVE-2022-34363: Dell Unisphere for PowerMax vApp authorization bypass

CVE-2022-34363 · Severity: medium · CVSS 6.5 · Published 2026-05-22

Technologies: Dell Unisphere For Powermax Virtual Appliance. Vendors: Dell.

Executive brief

Dell Unisphere for PowerMax is a management interface used to configure and monitor high-end enterprise storage systems. A security flaw in the virtual appliance version of this software could allow an attacker to bypass authorization checks. If exploited, this could allow unauthorized changes to the storage environment, potentially impacting data integrity and operational stability.

Technical details

An improper authorization vulnerability (CWE-285) exists in the Dell Unisphere for PowerMax virtual appliance (vApp). The flaw is located within the Unisphere for VMAX application component running inside the vApp environment. A remote attacker with low-privileged access can exploit this vulnerability over the network to bypass intended authorization restrictions. Successful exploitation allows the attacker to perform unauthorized actions that modify system state or configurations, though it does not directly facilitate data exfiltration (Confidentiality: None, Integrity: High). The issue is resolved in version 10.0.0.2.

Affected products

  • Dell Unisphere for PowerMax vApp Prior to 10.0.0.2

Timeline

  • 2026-05-22: advisory: Initial disclosure by Dell
  • 2026-05-22: disclosed

References

Related threats