Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23694


Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.


Published

2023-05-23T07:15:10.317

Last Modified

2024-11-21T07:46:40.610

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell vxrail_hyperconverged_infrastructure < 7.0.450 Yes

References