CVE-2023-44277

HIGH

Dell PowerProtect DD < 7.13.0.10 - OS Command Injection via CLI

Title source: llm
STIX 2.1

Description

Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 23.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (9)
dell/apex_protection_storage < 6.2.1.110
dell/emc_data_domain_os < 6.2.1.110
dell/emc_data_domain_os 7.10 - 7.10.1.15
dell/emc_data_domain_os 7.7 - 7.7.5.25
dell/powerprotect_data_domain < 6.2.1.110
dell/powerprotect_data_domain_management_center < 6.2.1.110
dell/powerprotect_data_domain_management_center 7.10 - 7.10.1.15
dell/powerprotect_data_domain_management_center 7.7 - 7.7.5.25
dell/powerprotect_data_protection < 2.7.6
Published Dec 14, 2023
Tracked Since Feb 18, 2026