CVE-2024-37139

MEDIUM

Dell Data Domain Operating System < 7.7.5.40 - Denial of Service

Title source: rule
STIX 2.1

Description

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to temporary resource constraint of system application. Exploitation may lead to denial of service of the application.

Scores

CVSS v3 6.5
EPSS 0.0124
EPSS Percentile 79.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-664
Status published
Products (1)
dell/data_domain_operating_system < 7.7.5.40
Published Jun 26, 2024
Tracked Since Feb 18, 2026