CVE-2024-0170: OS Command Injection
Published Feb 12, 2024
·Updated
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svccava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
Affected Software
1 affected component
Dell Unity Operating Environment<5.4.0.0.5.094
Event History
Feb 12, 2024
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0170?
CVE-2024-0170 is classified as a high-severity OS Command Injection vulnerability.
2
How do I fix CVE-2024-0170?
To fix CVE-2024-0170, upgrade your Dell Unity systems to version 5.4 or later.
3
Who can exploit CVE-2024-0170?
An authenticated attacker with access to the Dell Unity system can exploit CVE-2024-0170.
4
What impact does CVE-2024-0170 have?
CVE-2024-0170 allows attackers to escape the restricted shell and execute arbitrary commands with root privileges.
5
In which versions is CVE-2024-0170 present?
CVE-2024-0170 affects all Dell Unity Operating Environment versions prior to 5.4.