CVE-2023-44285Insufficient Granularity of Access Control in Dell Apex Protection Storage

Severity
7.8HIGHNVD
EPSS
0.1%
top 80.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14

Description

Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDdell/powerprotect_data_domain7.07.12.0.0+1
CVEListV5dell/powerprotect_ddVersions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110
NVDdell/emc_data_domain_os7.07.12.0.0+3

🔴Vulnerability Details

2
GHSA
GHSA-qr8x-cpgm-547r: Dell PowerProtect DD, versions prior to 72023-12-14
CVEList
CVE-2023-44285: Dell PowerProtect DD, versions prior to 72023-12-14
CVE-2023-44285 — Dell vulnerability | cvebase