← Vulnerability feed

Vulnerability record · CVE-2022-29084 · published 2 June 2022

CVE-2022-29084: Dell unity operating environment improper restriction of authentication attempts vulnerability

Dell · Unity Operating Environment

Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.

9.8 CVSS 3.1 Critical EPSS 1.9% · top 20.6% CWE-307 · Improper restriction of authentication attempts
9.8CVSS 3.1 base score, v2 10.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29084 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-36604Dell Unity OS Command Injection Allows Unauthenticated Remote Code ExecutionDell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in the Unity Operating Environment. An unauthenticated remote attacke…EPSS 64%analysed9.8CVE-2024-49601Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.5%9.8CVE-2025-22398Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 2.0%9.1CVE-2025-24383Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.1%8.8CVE-2025-24381Dell unity operating environment open redirect vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker wi…EPSS 1.4%7.8CVE-2026-22277Dell unity operating environment os command injection vulnerabilityDell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul…EPSS 0.62%7.8CVE-2026-21418Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln…EPSS 0.62%7.8CVE-2025-43942Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2022-29084), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.