CVE-2022-31231 MEDIUM

CVE-2022-31231

Vendor Dell
Product ECS
Weakness CWE-284
Published May 22, 2026
Last update May 23, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.

Key dates

02Disclosure timeline

May 22, 2026 CVE published
May 23, 2026 Record updated