Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22223


Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.


Published

2024-02-12T19:15:11.497

Last Modified

2024-11-21T08:55:50.017

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell unity_operating_environment < 5.4.0.0.5.094 Yes

References