← Back

CVE-2023-44277

nvd nist
Published: Dec 14, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

Affected (13)

5 products
Powerprotect Data Protection
Apex Protection Storage
Emc Data Domain Os
Powerprotect Data Domain
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 2.7.6
Running on/withPlatform Versions
Dell
Dp4400
All versions
Dell
Dp5900
All versions
Configuration B
12 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Dell
Before 6.2.1.110
From 7.0 to 7.10.1.15
Dell
Before 6.2.1.110
From 7.0 to 7.12.0.0
From 7.7 to 7.7.5.25
From 7.10 to 7.10.1.15
Dell
Before 6.2.1.110
From 7.0 to 7.12.0.0
Dell
Before 6.2.1.110
From 7.0 to 7.13.0.10
From 7.7 to 7.7.5.25
From 7.10 to 7.10.1.15
Running on/withPlatform Versions
Dell
Dd3300
All versions
Dell
Dd6400
All versions
Dell
Dd6900
All versions
Dell
Dd9400
All versions
Dell
Dd9900
All versions

Timeline

No history available yet.