CVE-2022-22555
Description
Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A locally authenticated attacker can execute arbitrary OS commands on Dell PowerStore via an OS command injection vulnerability, leading to privilege escalation.
Vulnerability
Dell EMC PowerStore contains an OS command injection vulnerability (CVE-2022-22555) in the underlying operating system. Affected versions include PowerStore T OS before Upgrade 3.0.0.0-1732745 [1]. The vulnerability allows a locally authenticated attacker to inject OS commands, which are then executed with the privileges of the vulnerable application.
Exploitation
An attacker must have local authentication to the PowerStore appliance. By crafting specific input to a vulnerable component, the attacker can inject arbitrary OS commands. No additional user interaction or network position beyond authenticated local access is required. The exact injection point is not publicly detailed in the available references.
Impact
Successful exploitation allows the attacker to execute arbitrary OS commands on the PowerStore underlying OS with the privileges of the vulnerable application. This can lead to an elevation of privilege, potentially enabling full control of the system or access to sensitive data.
Mitigation
Dell has released PowerStore T OS Upgrade 3.0.0.0-1732745 to address this vulnerability and all associated CVEs (except CVE-2022-32498, which affects the CLI tool) [1]. Users should apply the update from the Dell support site to mitigate the risk. No other workarounds are documented in the available references.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000201283mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.