Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22445


Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.


Published

2024-02-13T08:16:35.723

Last Modified

2024-11-21T08:56:18.427

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell powerprotect_data_manager ≤ 19.15 Yes

References