VYPR
Unrated severityNVD Advisory· Published Jul 20, 2022· Updated Sep 16, 2024

CVE-2022-31234

CVE-2022-31234

Description

Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell PowerStore Manager GUI lacks rate limiting, enabling remote brute-force password attacks leading to account takeover if weak passwords are used.

Vulnerability

Dell EMC PowerStore contains an Improper Restriction of Excessive Authentication Attempts vulnerability in the PowerStore Manager GUI. This allows a remote unauthenticated attacker to perform password brute-force attacks. The vulnerability affects PowerStore T OS versions before 3.0.0.0-1732745 [1].

Exploitation

An attacker can exploit this vulnerability by sending a large number of authentication requests to the PowerStore Manager GUI without any prior authentication or network position restrictions. The lack of rate limiting on login attempts enables systematic password guessing [1].

Impact

Successful exploitation allows the attacker to guess valid user credentials, potentially leading to account takeover. If weak passwords are used, the attacker could gain administrative or user-level access to the PowerStore system, resulting in unauthorized access, data disclosure, or further compromise [1].

Mitigation

Dell recommends upgrading to PowerStore T OS Upgrade 3.0.0.0-1732745 or later, which includes a fix for this vulnerability. The update is available via Dell Support [1]. No workarounds have been disclosed.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.