VYPR
Unrated severityNVD Advisory· Published Jul 20, 2022· Updated Sep 16, 2024

CVE-2022-22555

CVE-2022-22555

Description

Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A locally authenticated attacker can execute arbitrary OS commands on Dell PowerStore via an OS command injection vulnerability, leading to privilege escalation.

Vulnerability

Dell EMC PowerStore contains an OS command injection vulnerability (CVE-2022-22555) in the underlying operating system. Affected versions include PowerStore T OS before Upgrade 3.0.0.0-1732745 [1]. The vulnerability allows a locally authenticated attacker to inject OS commands, which are then executed with the privileges of the vulnerable application.

Exploitation

An attacker must have local authentication to the PowerStore appliance. By crafting specific input to a vulnerable component, the attacker can inject arbitrary OS commands. No additional user interaction or network position beyond authenticated local access is required. The exact injection point is not publicly detailed in the available references.

Impact

Successful exploitation allows the attacker to execute arbitrary OS commands on the PowerStore underlying OS with the privileges of the vulnerable application. This can lead to an elevation of privilege, potentially enabling full control of the system or access to sensitive data.

Mitigation

Dell has released PowerStore T OS Upgrade 3.0.0.0-1732745 to address this vulnerability and all associated CVEs (except CVE-2022-32498, which affects the CLI tool) [1]. Users should apply the update from the Dell support site to mitigate the risk. No other workarounds are documented in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.