CVE-2022-38017: StorSimple 8000 Series Elevation of Privilege Vulnerability
Overview
- Severity
- Medium (CVSS 6.8)
- CVSS Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2022-Oct
- Released
- 2022-10-11
- EPSS Score
- 0.98% (percentile: 76.8%)
FAQ
Where can I find more information about StorSimple 8000 Series?
StorSimple 8000 series is a hybrid cloud storage solution. Please see StorSimple 8000 series for more information.
According to the CVSS metric, the attack vector is physical (AV:P). What does that mean for this vulnerability?
An unauthenticated attacker needs to physically connect to a vulnerable StorSimple appliance to gain privileges to exploit this vulnerability.
Affected Products (1)
Azure
- Azure StorSimple 8000 Series
Revision History
- 2022-10-11: Information published.