CVE-2024-37138

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the application sending over an unauthorized file to the managed system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:23

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 4.1

23 Sep 2024, 21:03

Type Values Removed Values Added
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : 4.1
v2 : unknown
v3 : 6.8
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
Summary
  • (es) Dell PowerProtect DD, versiones anteriores a 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 en DDMC contienen una vulnerabilidad de Path Traversal relativo. Un atacante remoto con altos privilegios podría explotar esta vulnerabilidad, lo que provocaría que la aplicación envíe un archivo no autorizado al sistema administrado.
References () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000226148/dsa-2024-219-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities - Vendor Advisory
First Time Dell
Dell data Domain Operating System

26 Jun 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-26 04:15

Updated : 2024-11-21 09:23


NVD link : CVE-2024-37138

Mitre link : CVE-2024-37138

CVE.ORG link : CVE-2024-37138


JSON object : View

Products Affected

dell

  • data_domain_operating_system
CWE
CWE-23

Relative Path Traversal

NVD-CWE-Other