First published: Mon Feb 12 2024(Updated: )
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Unity Operating Environment | <5.4.0.0.5.094 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0165 is rated as a high severity vulnerability due to the potential for arbitrary command execution with root privileges.
To remediate CVE-2024-0165, update to Dell Unity Operating Environment version 5.4 or later.
CVE-2024-0165 affects Dell Unity systems running versions prior to 5.4.
CVE-2024-0165 is classified as an OS Command Injection vulnerability.
CVE-2024-0165 requires authentication, meaning it can only be exploited by authenticated users on the affected systems.