Research & Development
$ #

CVE-2023-44277

OS command injection vulnerability in the CLI

7.8 (High)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Dell PowerProtect DD

prior to: 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110

Jakub Brzozowski (redfr0g), Franciszek Kalinowski, Stanisław Koza

Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability, leading to privilege escalation.

PoC: TBA

  • 05-10-2023 - vulnerability reported to vendor
  • 10-01-2024 - public security advisory released