CVE-2023-44277
OS command injection vulnerability in the CLI
7.8 (High)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Dell PowerProtect DD
prior to: 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110
Jakub Brzozowski (redfr0g), Franciszek Kalinowski, Stanisław Koza
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability, leading to privilege escalation.
PoC: TBA
- 05-10-2023 - vulnerability reported to vendor
- 10-01-2024 - public security advisory released