First published: Mon Feb 12 2024(Updated: )
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Operating Environment | <5.4.0.0.5.094 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0166 is considered a critical severity vulnerability due to its potential for executing arbitrary OS commands with elevated privileges.
To fix CVE-2024-0166, upgrade to Dell Unity Operating Environment version 5.4 or later.
CVE-2024-0166 affects Dell Unity operating environments prior to version 5.4.
CVE-2024-0166 is an OS Command Injection vulnerability found in the svc_tcpdump utility.
CVE-2024-0166 requires authentication, so exploitation is limited to authenticated users.