PT-2024-20659 · Dell · Dell Powerprotect Dm5500

Published

2024-05-08

·

Updated

2024-05-08

·

CVE-2024-24908

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerProtect DM5500 versions 5.15.0.0 and prior
Description The issue allows a remote attacker with high privileges to potentially exploit an Arbitrary File Delete via Path Traversal vulnerability, leading to the deletion of arbitrary files stored on the server filesystem.
Recommendations For Dell PowerProtect DM5500 versions 5.15.0.0 and prior, consider restricting access to the server filesystem to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-24908

Affected Products

Dell Powerprotect Dm5500