CVE-2023-44277
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
Affected (13)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.6 |
| Running on/with | Platform Versions |
|---|---|
Dell Dp4400 | All versions |
Dell Dp5900 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.2.1.110 | |
| Before 6.2.1.110 | |
| Before 6.2.1.110 | |
| Before 6.2.1.110 |
| Running on/with | Platform Versions |
|---|---|
Dell Dd3300 | All versions |
Dell Dd6400 | All versions |
Dell Dd6900 | All versions |
Dell Dd9400 | All versions |
Dell Dd9900 | All versions |
References (2)
Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.