CVE-2022-33923
Description
Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A locally authenticated attacker can execute arbitrary OS commands on Dell PowerStore T, leading to full system compromise, before version 3.0.0.0.
Vulnerability
CVE-2022-33923 is an OS command injection vulnerability in the Dell PowerStore T environment. Affected versions are PowerStore T OS versions prior to 3.0.0.0-1732745 [1]. The flaw allows a locally authenticated attacker to inject arbitrary OS commands into the underlying operating system through a vulnerable input field or command parameter [1].
Exploitation
An attacker must have local authentication to the PowerStore T appliance. No special privileges beyond standard user access are required. By crafting a malicious input that includes command separators or shell metacharacters, the attacker can cause the application to execute attacker-controlled commands on the PowerStore underlying OS [1]. The attacker then runs arbitrary commands at the OS level.
Impact
Successful exploitation results in arbitrary OS command execution with the privileges of the PowerStore application process. This can lead to full system takeover, including access to all data, modification of system configuration, and potential lateral movement within the network [1]. The impact is critical.
Mitigation
Dell has released PowerStore T OS Upgrade version 3.0.0.0-1732745 to address this vulnerability [1]. Users should upgrade to this version or later. There is no known workaround for the vulnerability. The advisory recommends immediate patching as the sole mitigation [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <3.0.0.0
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000201283mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.