First published: Thu Dec 14 2023(Updated: )
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by an attacker
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Dell PowerProtect Data Protection | <2.7.6 | |
Any of | ||
Dell DP4400 | ||
Dell DP5900 Firmware | ||
All of | ||
Any of | ||
Dell Apex Protection Storage | <6.2.1.110 | |
Dell Apex Protection Storage | >=7.0<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.12.0.0 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.13.0.10 | |
EMC Data Domain Operating System | <6.2.1.110 | |
EMC Data Domain Operating System | >=7.0<7.12.0.0 | |
EMC Data Domain Operating System | >=7.7<7.7.5.25 | |
EMC Data Domain Operating System | >=7.10<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | >=7.7<7.7.5.25 | |
Dell PowerProtect Data Domain Management Center | >=7.10<7.10.1.15 | |
Any of | ||
Dell DD3300 | ||
Dell DD6400 | ||
Dell DD6900 | ||
Dell DD9400 | ||
Dell Dd9900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44279 is a high severity vulnerability that allows local high privileged attackers to bypass security restrictions.
To fix CVE-2023-44279, update Dell PowerProtect DD to versions 7.13.0.10 or later, or any appropriate LTS version as specified.
CVE-2023-44279 affects Dell PowerProtect DD versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and 6.2.1.110.
CVE-2023-44279 cannot be exploited remotely as it requires local high privileged access.
CVE-2023-44279 impacts Dell PowerProtect DD, Dell Apex Protection Storage, and Dell Data Domain Management Center based on specific versions.