Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-48668


Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerability in an admin operation. A local high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the managed system application's underlying OS with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker on a managed system of DDMC.


Published

2023-12-14T16:15:50.257

Last Modified

2024-11-21T08:32:13.863

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell powerprotect_data_domain_management_center < 6.2.1.110 Yes
Application dell powerprotect_data_domain_management_center < 7.13.0.10 Yes
Operating System dell powerprotect_data_domain_management_center < 7.7.5.25 Yes
Operating System dell powerprotect_data_domain_management_center < 7.10.1.15 Yes

References