CVE-2022-31228 is a critical bruteforce vulnerability affecting Dell EMC XtremIO versions prior to X2 6.4.0-22, specifically impacting the management server, X1, and X2 products. With a CVSS score of 9.8, this vulnerability allows a remote, unauthenticated attacker to potentially gain full administrative access due to low attack complexity and no user interaction required. Despite its critical severity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.0-22CPE matchmatch criteria | cpe:2.3:a:dell:xtremio_management_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.