CVE-2023-44291

HIGH

Dell PowerProtect Data Manager DM5500 Firmware < 5.14.0.0 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

Scores

CVSS v3 7.2
EPSS 0.0289
EPSS Percentile 86.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
dell/powerprotect_data_manager_dm5500_firmware < 5.14.0.0
Published Dec 04, 2023
Tracked Since Feb 18, 2026