First published: Thu Dec 14 2023(Updated: )
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS to bypass security restriction. Exploitation may lead to a system take over by an attacker.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Dell Apex Protection Storage | <6.2.1.110 | |
Dell Apex Protection Storage | >=7.0<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.12.0.0 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.13.0.10 | |
EMC Data Domain Operating System | <6.2.1.110 | |
EMC Data Domain Operating System | >=7.0<7.12.0.0 | |
EMC Data Domain Operating System | >=7.7<7.7.5.25 | |
EMC Data Domain Operating System | >=7.10<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | >=7.7<7.7.5.25 | |
Dell PowerProtect Data Domain Management Center | >=7.10<7.10.1.15 | |
Any of | ||
Dell DD3300 | ||
Dell DD6400 | ||
Dell DD6900 | ||
Dell DD9400 | ||
Dell Dd9900 | ||
All of | ||
Dell PowerProtect Data Protection | <2.7.6 | |
Any of | ||
Dell DP4400 | ||
Dell DP5900 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48667 has been classified as a high severity vulnerability due to the potential for remote OS command execution by high privileged attackers.
To fix CVE-2023-48667, you should upgrade to Dell PowerProtect DD version 7.13.0.10 or later, LTS 7.7.5.25, or LTS 7.10.1.15.
CVE-2023-48667 affects versions of Dell PowerProtect DD prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, and version 6.2.1.110 and earlier.
Products such as Dell PowerProtect DD, Dell Apex Protection Storage, and Dell Powerprotect Data Domain Management Center prior to the specified versions are affected by CVE-2023-48667.
CVE-2023-48667 is classified as an OS command injection vulnerability found in the administrator command-line interface.