CVE-2024-0165: OS Command Injection
Published Feb 12, 2024
·Updated
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svcacldbdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.
Affected Software
1 affected component
Dell Unity Operating Environment<5.4.0.0.5.094
Event History
Feb 12, 2024
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0165?
CVE-2024-0165 is rated as a high severity vulnerability due to the potential for arbitrary command execution with root privileges.
2
How do I fix CVE-2024-0165?
To remediate CVE-2024-0165, update to Dell Unity Operating Environment version 5.4 or later.
3
Who is affected by CVE-2024-0165?
CVE-2024-0165 affects Dell Unity systems running versions prior to 5.4.
4
What type of vulnerability is CVE-2024-0165?
CVE-2024-0165 is classified as an OS Command Injection vulnerability.
5
Can CVE-2024-0165 be exploited remotely?
CVE-2024-0165 requires authentication, meaning it can only be exploited by authenticated users on the affected systems.