CVE-2024-51534Path Traversal: '\..\filename' in Dell Data Domain Operating System

Severity
7.1HIGHNVD
EPSS
0.1%
top 66.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1

Description

Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on the server filesystem. Exploitation could lead to denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5dell/powerprotect_dd7.7.1.08.1.0.10+2
NVDdell/data_domain_operating_system7.10.1.07.10.1.50+2

🔴Vulnerability Details

2
GHSA
GHSA-qww8-25fx-j9hq: Dell PowerProtect DD versions prior to DDOS 82025-02-01
CVEList
CVE-2024-51534: Dell PowerProtect DD versions prior to DDOS 82025-02-01
CVE-2024-51534 — Path Traversal: '\..\filename' in Dell | cvebase