CVE-2023-44278: Path Traversal
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44278?
CVE-2023-44278 is classified as a high severity vulnerability due to the potential for unprivileged access to sensitive OS files.
How do I fix CVE-2023-44278?
To fix CVE-2023-44278, upgrade to Dell PowerProtect versions 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, or 6.2.1.110 or later.
What causes the CVE-2023-44278 vulnerability?
CVE-2023-44278 is caused by a path traversal vulnerability that allows local high privileged attackers to access unauthorized files.
Which versions of Dell PowerProtect are affected by CVE-2023-44278?
Versions of Dell PowerProtect prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and 6.2.1.110 are affected by CVE-2023-44278.
Who can exploit the CVE-2023-44278 vulnerability?
CVE-2023-44278 can be exploited by local high privileged attackers who have access to the system.