PT-2023-29188 · Dell · Dell Powerprotect Dd

Franciszek Kalinowski

+3

·

Published

2023-12-14

·

Updated

2023-12-27

·

CVE-2023-44285

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerProtect DD versions prior to 7.13.0.10 Dell PowerProtect DD LTS versions prior to 7.7.5.25 Dell PowerProtect DD LTS versions prior to 7.10.1.15 Dell PowerProtect DD version 6.2.1.110
Description The issue is related to an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability, leading to escalation of privilege.
Recommendations For versions prior to 7.13.0.10, update to version 7.13.0.10 or later. For LTS versions prior to 7.7.5.25, update to version 7.7.5.25 or later. For LTS versions prior to 7.10.1.15, update to version 7.10.1.15 or later. For version 6.2.1.110, update to a version later than 6.2.1.110.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-44285

Affected Products

Dell Powerprotect Dd