CVE-2023-44278

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dell:powerprotect_data_protection:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:dp4400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dp5900:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:h:dell:dd3300:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd6900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dd9900:-:*:*:*:*:*:*:*
OR cpe:2.3:a:dell:apex_protection_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:apex_protection_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:virtual:*:*:*
cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:virtual:*:*:*
cpe:2.3:a:dell:powerprotect_data_domain_management_center:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerprotect_data_domain_management_center:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2022:*:*:*
cpe:2.3:o:dell:emc_data_domain_os:*:*:*:*:lts2023:*:*:*
cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2022:*:*:*
cpe:2.3:o:dell:powerprotect_data_domain_management_center:*:*:*:*:lts2023:*:*:*

History

No history.

Information

Published : 2023-12-14 16:15

Updated : 2023-12-27 19:32


NVD link : CVE-2023-44278

Mitre link : CVE-2023-44278

CVE.ORG link : CVE-2023-44278


JSON object : View

Products Affected

dell

  • dd6400
  • powerprotect_data_protection
  • dd9400
  • dp4400
  • dd9900
  • emc_data_domain_os
  • dp5900
  • apex_protection_storage
  • powerprotect_data_domain
  • dd6900
  • powerprotect_data_domain_management_center
  • dd3300
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')