Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's underlying OS with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
History

Mon, 23 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell data Domain Operating System
CPEs cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell data Domain Operating System

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2024-06-26T03:54:38.461Z

Updated: 2024-08-02T03:50:54.530Z

Reserved: 2024-06-03T12:10:32.206Z

Link: CVE-2024-37140

cve-icon Vulnrichment

Updated: 2024-08-02T03:50:54.530Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-26T04:15:13.667

Modified: 2024-09-23T21:01:55.587

Link: CVE-2024-37140

cve-icon Redhat

No data.