First published: Mon Feb 12 2024(Updated: )
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Operating Environment | <5.4.0.0.5.094 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22228 is considered a high severity vulnerability due to the potential for authenticated attackers to execute arbitrary commands with root privileges.
To fix CVE-2024-22228, upgrade to Dell Unity software version 5.4 or later.
CVE-2024-22228 affects Dell Unity operating environment versions prior to 5.4.
An authenticated attacker can exploit CVE-2024-22228 to escape the restricted shell and execute arbitrary operating system commands with root privileges.
The exploitation of CVE-2024-22228 requires authentication, thus making it less likely to be exploited remotely without valid credentials.