CVE-2023-32449

Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dell:powerstoret_os:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*

History

28 Jun 2023, 15:21

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-22 07:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-32449

Mitre link : CVE-2023-32449

CVE.ORG link : CVE-2023-32449


JSON object : View

Products Affected

dell

  • powerstore_9000t
  • powerstore_1000t
  • powerstore_5000t
  • powerstore_9200t
  • powerstore_3200t
  • powerstore_1200t
  • powerstore_5200t
  • powerstore_3000t
  • powerstore_7000t
  • powerstoret_os
  • powerstore_500t
CWE
CWE-347

Improper Verification of Cryptographic Signature