CVE-2023-44277: OS Command Injection
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44277?
CVE-2023-44277 is classified as a low severity OS command injection vulnerability.
How do I fix CVE-2023-44277?
To fix CVE-2023-44277, upgrade to Dell PowerProtect DD version 7.13.0.10 or later, or relevant LTS versions.
Who is affected by CVE-2023-44277?
CVE-2023-44277 affects users running Dell PowerProtect DD prior to version 7.13.0.10 and some other Dell storage products.
What could happen if CVE-2023-44277 is exploited?
If exploited, CVE-2023-44277 could allow a local low privileged attacker to execute arbitrary OS commands.
Is CVE-2023-44277 exploitable remotely?
No, CVE-2023-44277 is not remotely exploitable and requires local access to the affected systems.