CVE-2024-45759

EUVD-2024-41585
Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to unauthorized execution of certain commands to overwrite system config of the application. Exploitation may lead to denial of service of system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
dellCNA
6.8 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
delldata_domain_operating_system
7.7.1.0 ≤
𝑥
< 7.7.5.50
delldata_domain_operating_system
7.10.0.0 ≤
𝑥
< 7.10.1.40
delldata_domain_operating_system
7.13.0.0 ≤
𝑥
< 7.13.1.10
delldata_domain_operating_system
8.0.0.0 ≤
𝑥
< 8.1.0.0
𝑥
= Vulnerable software versions