CVE-2024-25955

EUVD-2024-23257
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.
OS Command Injection
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
dellsolutions_enabler_virtual_appliance
𝑥
< 9.2.4.6
dellunisphere_for_powermax_virtual_appliance
𝑥
< 9.2.4.9
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
dellunisphere_for_powermax_virtual_appliance
𝑥
< 9.2.4.9
ADP
dellsolutions_enabler_virtual_appliance
𝑥
< 9.2.4.6
ADP
dellunisphere_for_powermax
𝑥
< 5978
ADP