PT-2023-29185 · Dell · Dell Powerprotect Dd

Published

2023-12-14

·

Updated

2023-12-27

·

CVE-2023-44278

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerProtect DD versions prior to 7.13.0.10 Dell PowerProtect DD LTS versions prior to 7.7.5.25 Dell PowerProtect DD LTS versions prior to 7.10.1.15 Dell PowerProtect DD version 6.2.1.110
Description A path traversal vulnerability exists, allowing a local high privileged attacker to potentially exploit this issue and gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.
Recommendations For versions prior to 7.13.0.10, update to version 7.13.0.10 or later. For LTS versions prior to 7.7.5.25, update to version 7.7.5.25 or later. For LTS versions prior to 7.10.1.15, update to version 7.10.1.15 or later. For version 6.2.1.110, update to a version later than 6.2.1.110.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-44278

Affected Products

Dell Powerprotect Dd