Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by an attacker
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Apex Protection Storage
Subscribe
Dd3300
Subscribe
Dd6400
Subscribe
Dd6900
Subscribe
Dd9400
Subscribe
Dd9900
Subscribe
Dp4400
Subscribe
Dp5900
Subscribe
Emc Data Domain Os
Subscribe
Powerprotect Data Domain
Subscribe
Powerprotect Data Domain Management Center
Subscribe
Powerprotect Data Protection
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48635 | Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by an attacker |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:*:*:*:* cpe:2.3:a:dell:powerprotect_data_domain:-:*:*:*:lts:*:*:* |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-10-01T14:44:19.118Z
Reserved: 2023-09-28T09:25:45.713Z
Link: CVE-2023-44279
Updated: 2024-08-02T19:59:51.987Z
Status : Modified
Published: 2023-12-14T16:15:46.017
Modified: 2024-11-21T08:25:34.707
Link: CVE-2023-44279
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD