First published: Mon Feb 12 2024(Updated: )
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Unity Operating Environment | <5.4.0.0.5.094 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0170 is classified as a high-severity OS Command Injection vulnerability.
To fix CVE-2024-0170, upgrade your Dell Unity systems to version 5.4 or later.
An authenticated attacker with access to the Dell Unity system can exploit CVE-2024-0170.
CVE-2024-0170 allows attackers to escape the restricted shell and execute arbitrary commands with root privileges.
CVE-2024-0170 affects all Dell Unity Operating Environment versions prior to 5.4.