VYPR
Unrated severityNVD Advisory· Published Jun 2, 2022· Updated Sep 17, 2024

CVE-2022-22556

CVE-2022-22556

Description

Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell PowerStore UI vulnerability allows unauthenticated remote attackers to cause denial of service via uncontrolled resource consumption.

Vulnerability

CVE-2022-22556 is an Uncontrolled Resource Consumption vulnerability in the PowerStore User Interface component of Dell PowerStore. The vulnerability affects all versions prior to the fix released in the DSA-2022-014 security update. The issue resides in the UI code where insufficient resource limits allow an attacker to trigger excessive resource usage, leading to denial of service.[1]

Exploitation

A remote unauthenticated attacker can exploit this vulnerability by sending crafted requests to the PowerStore User Interface over the network. The CVSS vector indicates the attack complexity is high (AC:H), meaning the attacker may need to rely on specific conditions or timing to cause resource exhaustion. No authentication or user interaction is required.[1]

Impact

Successful exploitation results in denial of service (availability impact rated low per CVSS). The UI becomes unresponsive, potentially interrupting management operations. No confidentiality or integrity impact is expected. The CVSS base score is 3.7 (low severity).[1]

Mitigation

Dell released a security update (DSA-2022-014) in June 2022. Users should upgrade to the fixed PowerStore version as specified in the advisory. Restricting network access to the PowerStore management interface can reduce exposure.[1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.