CVE-2023-44278

MEDIUM

Dell PowerProtect DD < 7.13.0.10 - Path Traversal and Arbitrary File Write

Title source: llm
STIX 2.1

Description

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.

Scores

CVSS v3 6.7
EPSS 0.0008
EPSS Percentile 23.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (9)
dell/apex_protection_storage < 6.2.1.110
dell/emc_data_domain_os < 6.2.1.110
dell/emc_data_domain_os 7.10 - 7.10.1.15
dell/emc_data_domain_os 7.7 - 7.7.5.25
dell/powerprotect_data_domain < 6.2.1.110
dell/powerprotect_data_domain_management_center < 6.2.1.110
dell/powerprotect_data_domain_management_center 7.10 - 7.10.1.15
dell/powerprotect_data_domain_management_center 7.7 - 7.7.5.25
dell/powerprotect_data_protection < 2.7.6
Published Dec 14, 2023
Tracked Since Feb 18, 2026