PT-2019-16651 · Dell Emc · Dell Vnx2 Oe For File

Published

2019-02-07

·

Updated

2019-10-09

·

CVE-2019-3704

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC VNX2 OE for File versions prior to 8.1.9.236
Description The issue is related to an OS command injection vulnerability in VNX Control Station. A local authenticated malicious user could potentially execute arbitrary OS commands as root due to inadequate restriction configured in sudores.
Recommendations For versions prior to 8.1.9.236, update to version 8.1.9.236 or later to resolve the issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3704

Affected Products

Dell Vnx2 Oe For File