First published: Mon Dec 04 2023(Updated: )
Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Dell PowerProtect Data Manager Dm5500 Firmware | <=5.14.0.0 | |
Dell PowerProtect Data Manager Dm5500 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-44291.
The severity of CVE-2023-44291 is high with a CVSS score of 7.2.
The vulnerability in Dell DM5500 5.14.0.0 manifests as an OS command injection vulnerability in the PPOE component.
A remote attacker with high privileges can potentially exploit CVE-2023-44291 to execute arbitrary OS commands on the underlying OS with the privileges of the vulnerable application.
Yes, there is a security update available for Dell DM5500 to address this vulnerability. Please refer to the Dell support website for more information.