PT-2023-30887 · Dell · Dell Vapp Manager

33A6099

·

Published

2023-12-14

·

Updated

2023-12-19

·

CVE-2023-48665

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell vApp Manager versions prior to 9.2.4.x
Description A command injection vulnerability exists, allowing a remote malicious user with high privileges to potentially exploit this issue, leading to the execution of arbitrary OS commands on the affected system.
Recommendations For versions prior to 9.2.4.x, update to version 9.2.4.x or later to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation by a remote malicious user with high privileges.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-48665

Affected Products

Dell Vapp Manager