PT-2024-15364 · Dell · Dell Unity

Published

2024-02-12

·

Updated

2024-02-20

·

CVE-2024-0165

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Unity versions prior to 5.4
Description The issue is an OS Command Injection Vulnerability in the svc acldb dump utility of Dell Unity. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary operating system commands with root privileges.
Recommendations For versions prior to 5.4, update to version 5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the svc acldb dump utility until a patch is available.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-0165

Affected Products

Dell Unity