Description
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's underlying OS with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36462 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's underlying OS with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker. |
References
History
Mon, 23 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell data Domain Operating System |
|
| CPEs | cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell
Dell data Domain Operating System |
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-02T03:50:54.530Z
Reserved: 2024-06-03T12:10:32.206Z
Link: CVE-2024-37140
Updated: 2024-08-02T03:50:54.530Z
Status : Modified
Published: 2024-06-26T04:15:13.667
Modified: 2024-11-21T09:23:17.183
Link: CVE-2024-37140
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD