PT-2023-29185 · Dell · Dell Powerprotect Dd

CVE-2023-44278

·

Publicado

2023-12-14

·

Atualizado

2023-12-27

CVSS v3.1

6.7

Média

VetorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerProtect DD versions prior to 7.13.0.10 Dell PowerProtect DD LTS versions prior to 7.7.5.25 Dell PowerProtect DD LTS versions prior to 7.10.1.15 Dell PowerProtect DD version 6.2.1.110
Description A path traversal vulnerability exists, allowing a local high privileged attacker to potentially exploit this issue and gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.
Recommendations For versions prior to 7.13.0.10, update to version 7.13.0.10 or later. For LTS versions prior to 7.7.5.25, update to version 7.7.5.25 or later. For LTS versions prior to 7.10.1.15, update to version 7.10.1.15 or later. For version 6.2.1.110, update to a version later than 6.2.1.110.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-44278

Produtos afetados

Dell Powerprotect Dd