CVE-2023-44278
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.
Published:Dec 14, 2023
Last Modified:Nov 21, 2024
EPS:Dec 14, 2023
EPSS Score:0.0008
CVSS Score:6.7
Affected Products
Vendor
Product
Action
Vendor
Dell
Product
Apex Protection Storage
Dell
Apex Protection Storage
Vendor
Dell
Product
Dd3300
Dell
Dd3300
Vendor
Dell
Product
Dd6400
Dell
Dd6400
Vendor
Dell
Product
Dd6900
Dell
Dd6900
Vendor
Dell
Product
Dd9400
Dell
Dd9400
Vendor
Dell
Product
Dd9900
Dell
Dd9900
Vendor
Dell
Product
Dp4400
Dell
Dp4400
Vendor
Dell
Product
Dp5900
Dell
Dp5900
Vendor
Dell
Product
Emc Data Domain Os
Dell
Emc Data Domain Os
Vendor
Dell
Product
Powerprotect Data Domain
Dell
Powerprotect Data Domain
Vendor
Dell
Product
Powerprotect Data Domain Management Center
Dell
Powerprotect Data Domain Management Center
Vendor
Dell
Product
Powerprotect Data Protection
Dell
Powerprotect Data Protection
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
