CVE-2023-43068
HIGHDell SmartFabric Storage Software <1.4 - Command Injection
Title source: llmDescription
Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands.
References (1)
Core 1
Core References
Scores
CVSS v3
7.8
EPSS
0.0034
EPSS Percentile
56.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
dell/smartfabric_storage_software
< 1.4.1
Published
Oct 05, 2023
Tracked Since
Feb 18, 2026