VYPR
Unrated severityNVD Advisory· Published Jul 20, 2022· Updated Sep 16, 2024

CVE-2022-33923

CVE-2022-33923

Description

Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A locally authenticated attacker can execute arbitrary OS commands on Dell PowerStore T, leading to full system compromise, before version 3.0.0.0.

Vulnerability

CVE-2022-33923 is an OS command injection vulnerability in the Dell PowerStore T environment. Affected versions are PowerStore T OS versions prior to 3.0.0.0-1732745 [1]. The flaw allows a locally authenticated attacker to inject arbitrary OS commands into the underlying operating system through a vulnerable input field or command parameter [1].

Exploitation

An attacker must have local authentication to the PowerStore T appliance. No special privileges beyond standard user access are required. By crafting a malicious input that includes command separators or shell metacharacters, the attacker can cause the application to execute attacker-controlled commands on the PowerStore underlying OS [1]. The attacker then runs arbitrary commands at the OS level.

Impact

Successful exploitation results in arbitrary OS command execution with the privileges of the PowerStore application process. This can lead to full system takeover, including access to all data, modification of system configuration, and potential lateral movement within the network [1]. The impact is critical.

Mitigation

Dell has released PowerStore T OS Upgrade version 3.0.0.0-1732745 to address this vulnerability [1]. Users should upgrade to this version or later. There is no known workaround for the vulnerability. The advisory recommends immediate patching as the sole mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.