First published: Mon Feb 12 2024(Updated: )
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Operating Environment | <5.4.0.0.5.094 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22224 is classified as a high-severity OS command injection vulnerability.
To fix CVE-2024-22224, update your Dell Unity Operating Environment to version 5.4 or later.
CVE-2024-22224 affects users of Dell Unity Operating Environment versions prior to 5.4.
CVE-2024-22224 requires authentication, so exploitation must come from an authenticated attacker.
An attacker exploiting CVE-2024-22224 can escape the restricted shell and execute arbitrary operating system commands with root privileges.