CVE-2024-45759

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to unauthorized execution of certain commands to overwrite system config of the application. Exploitation may lead to denial of service of system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
dellCNA
6.8 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
delldata_domain_operating_system
7.7.1.0 ≤
𝑥
< 7.7.5.50
delldata_domain_operating_system
7.10.0.0 ≤
𝑥
< 7.10.1.40
delldata_domain_operating_system
7.13.0.0 ≤
𝑥
< 7.13.1.10
delldata_domain_operating_system
8.0.0.0 ≤
𝑥
< 8.1.0.0
𝑥
= Vulnerable software versions