CVE-2023-44279: OS Command Injection
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by an attacker
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44279?
CVE-2023-44279 is a high severity vulnerability that allows local high privileged attackers to bypass security restrictions.
How do I fix CVE-2023-44279?
To fix CVE-2023-44279, update Dell PowerProtect DD to versions 7.13.0.10 or later, or any appropriate LTS version as specified.
Which versions are affected by CVE-2023-44279?
CVE-2023-44279 affects Dell PowerProtect DD versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and 6.2.1.110.
Can CVE-2023-44279 be exploited remotely?
CVE-2023-44279 cannot be exploited remotely as it requires local high privileged access.
What products are impacted by CVE-2023-44279?
CVE-2023-44279 impacts Dell PowerProtect DD, Dell Apex Protection Storage, and Dell Data Domain Management Center based on specific versions.