CVE-2023-43069
HIGHDell SmartFabric Storage Software <1.4 - Command Injection
Title source: llmDescription
Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local attacker could potentially exploit this vulnerability, leading to possible injection of parameters to curl or docker.
References (1)
Core 1
Core References
Scores
CVSS v3
7.8
EPSS
0.0008
EPSS Percentile
24.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
dell/smartfabric_storage_software
< 1.4.1
Published
Oct 05, 2023
Tracked Since
Feb 18, 2026