CVE-2023-48667
Last modified
CVE-2023-48667 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS to bypass security restriction. EPSS estimates a 1.78% chance of exploitation in the next 30 days.
Description
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS to bypass security restriction. Exploitation may lead to a system take over by an attacker.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Apex Protection Storage | < 6.2.1.110 |
| Dell | Apex Protection Storage | >= 7.0, < 7.10.1.15 |
| Dell | Powerprotect Data Domain | < 6.2.1.110 |
| Dell | Powerprotect Data Domain | >= 7.0, < 7.12.0.0 |
| Dell | Powerprotect Data Domain Management Center | < 6.2.1.110 |
| Dell | Powerprotect Data Domain Management Center | >= 7.0, < 7.13.0.10 |
| Dell | Emc Data Domain Os | < 6.2.1.110 |
| Dell | Emc Data Domain Os | >= 7.0, < 7.12.0.0 |
| Dell | Emc Data Domain Os | >= 7.7, < 7.7.5.25 |
| Dell | Emc Data Domain Os | >= 7.10, < 7.10.1.15 |
| Dell | Powerprotect Data Domain Management Center | >= 7.7, < 7.7.5.25 |
| Dell | Powerprotect Data Domain Management Center | >= 7.10, < 7.10.1.15 |
| Dell | Powerprotect Data Protection | < 2.7.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-48667?
How severe is CVE-2023-48667?
How do I fix CVE-2023-48667?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-48660 Dell vApp Manger, versions prior to 9.2.4.x contain an arbi…7.5
- CVE-2023-48661 Dell vApp Manager, versions prior to 9.2.4.x contain an arb…4.9
- CVE-2023-48662 Dell vApp Manager, versions prior to 9.2.4.x contain a comm…7.2
- CVE-2023-48663 Dell vApp Manager, versions prior to 9.2.4.x contain a comm…7.2
- CVE-2023-48664 Dell vApp Manager, versions prior to 9.2.4.x contain a comm…7.2
- CVE-2023-48665 Dell vApp Manager, versions prior to 9.2.4.x contain a comm…7.2
- CVE-2023-48668 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.…6.7
- CVE-2023-4867A vulnerability was found in Xintian Smart Table Integrated …8.8
- CVE-2023-48670 Dell SupportAssist for Home PCs version 3.14.1 and prior ve…7.8
- CVE-2023-48671 Dell vApp Manager, versions prior to 9.2.4.x contain an inf…7.5
- CVE-2023-48674Dell Platform BIOS contains an Improper Null Termination vul…4.9
- CVE-2023-48676Sensitive information disclosure and manipulation due to mis…7.1
Are you affected by CVE-2023-48667?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
