OS Command Injection Vulnerability in Dell EMC PowerStore
CVE-2020-29499

6.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
19 July 2021

Summary

Dell EMC PowerStore, specifically versions earlier than 1.0.3.0.5.006, is susceptible to an OS Command Injection vulnerability in the PowerStore X environment. This security flaw allows an authenticated local attacker to execute arbitrary OS commands on the underlying operating system of the PowerStore. If exploited, this may enable the attacker to take control of the system. It is crucial for users of affected versions to implement security measures and update to the latest software to mitigate the risks associated with this vulnerability.

Affected Version(s)

PowerStore < unspecified

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.