Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Apex Protection Storage
Subscribe
Dd3300
Subscribe
Dd6400
Subscribe
Dd6900
Subscribe
Dd9400
Subscribe
Dd9900
Subscribe
Dp4400
Subscribe
Dp5900
Subscribe
Emc Data Domain Os
Subscribe
Powerprotect Data Domain
Subscribe
Powerprotect Data Domain Management Center
Subscribe
Powerprotect Data Protection
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48633 | Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-02T19:59:52.006Z
Reserved: 2023-09-28T09:25:45.713Z
Link: CVE-2023-44277
No data.
Status : Modified
Published: 2023-12-14T15:15:08.093
Modified: 2024-11-21T08:25:34.403
Link: CVE-2023-44277
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD