6.8
CVE-2024-37138
- EPSS 0.23%
- Veröffentlicht 26.06.2024 04:15:13
- Zuletzt bearbeitet 21.11.2024 09:23:16
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the application sending over an unauthorized file to the managed system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Data Domain Operating System Version < 7.7.5.40
Dell ≫ Data Domain Operating System Version >= 7.8.0.0 < 7.10.1.30
Dell ≫ Data Domain Operating System Version >= 7.11.0.0 < 7.13.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.451 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 2.3 | 4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
|
| security_alert@emc.com | 4.1 | 2.3 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.