CVE-2023-48667: OS Command Injection
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS to bypass security restriction. Exploitation may lead to a system take over by an attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48667?
CVE-2023-48667 has been classified as a high severity vulnerability due to the potential for remote OS command execution by high privileged attackers.
How do I fix CVE-2023-48667?
To fix CVE-2023-48667, you should upgrade to Dell PowerProtect DD version 7.13.0.10 or later, LTS 7.7.5.25, or LTS 7.10.1.15.
Which versions are affected by CVE-2023-48667?
CVE-2023-48667 affects versions of Dell PowerProtect DD prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and version 6.2.1.110 and earlier.
Is my Dell product affected by CVE-2023-48667?
Products such as Dell PowerProtect DD, Dell Apex Protection Storage, and Dell Powerprotect Data Domain Management Center prior to the specified versions are affected by CVE-2023-48667.
What type of vulnerability is CVE-2023-48667?
CVE-2023-48667 is classified as an OS command injection vulnerability found in the administrator command-line interface.