Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37140


Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's underlying OS with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.


Published

2024-06-26T04:15:13.667

Last Modified

2024-11-21T09:23:17.183

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dell data_domain_operating_system < 7.7.5.40 Yes
Operating System dell data_domain_operating_system < 7.10.1.30 Yes
Operating System dell data_domain_operating_system < 7.13.1.0 Yes

References