First published: Thu Dec 14 2023(Updated: )
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS commands on the affected system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Solutions Enabler | <9.2.4.5 | |
Dell EMC Unisphere | <9.2.4.7 | |
Dell PowerMax OS | =5978 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48664 is considered a high severity vulnerability due to its potential for remote command execution.
To mitigate CVE-2023-48664, upgrade to Dell vApp Manager version 9.2.4.x or later.
CVE-2023-48664 affects Dell Solutions Enabler Virtual Appliance, Dell Unisphere for Powermax Virtual Appliance, and Dell Powermax OS version 5978.
Organizations using the affected Dell virtual appliances with high privilege remote access are at risk from CVE-2023-48664.
Yes, CVE-2023-48664 can be exploited remotely by malicious users with high privileges.