CVE-2023-44291
HIGHDell PowerProtect Data Manager DM5500 Firmware < 5.14.0.0 - Authenticated OS Command Injection
Title source: llmDescription
Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
References (1)
Core 1
Core References
Scores
CVSS v3
7.2
EPSS
0.0289
EPSS Percentile
86.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (1)
dell/powerprotect_data_manager_dm5500_firmware
< 5.14.0.0
Published
Dec 04, 2023
Tracked Since
Feb 18, 2026