CVE-2023-25539: Code Injection
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Dell NetWorker vulnerability?
The vulnerability ID of this Dell NetWorker vulnerability is CVE-2023-25539.
What is the severity level of CVE-2023-25539?
The severity level of CVE-2023-25539 is critical with a value of 9.8.
What is the affected software?
The affected software is Dell NetWorker version up to 19.6.1.2.
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote unauthenticated attacker to execute arbitrary OS commands on the underlying OS.
Is there a security update available for this vulnerability?
Yes, Dell has released a security update for this vulnerability. Please refer to the Dell support page for more information.