CVE-2024-37140

EUVD-2024-36462
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's underlying OS with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
delldata_domain_operating_system
𝑥
< 7.7.5.40
delldata_domain_operating_system
7.8.0.0 ≤
𝑥
< 7.10.1.30
delldata_domain_operating_system
7.11.0.0 ≤
𝑥
< 7.13.1.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
dellpowerprotect_dd
7.0 ≤
𝑥
≤ 7.13
ADP
dellpowerprotect_dd
𝑥
< 2.7.7
ADP
dellpowerprotect_dd
𝑥
< 5.16.0.0
ADP