CVE-2024-25946

EUVD-2024-23248
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.
OS Command Injection
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
dellsolutions_enabler_virtual_appliance
𝑥
< 9.2.4.6
dellunisphere_for_powermax_virtual_appliance
𝑥
< 9.2.4.9
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
dellvirtual_appliance_manager
𝑥
< 9.2.4.9
ADP
dellvirtual_appliance_manager
𝑥
< 9.2.4.6
ADP
dellvirtual_appliance_manager
𝑥
< 5978
ADP