OS Command Injection Vulnerability in Dell NetWorker Software
CVE-2023-25539

9.8CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
31 May 2023

Summary

Dell NetWorker version 19.6.1.2 is vulnerable to an OS command injection flaw in the NetWorker client. This security issue allows remote unauthenticated attackers to execute arbitrary OS commands on the underlying system with the same privileges as the application. As a result, an attacker could gain complete control of the affected system. To mitigate this risk, Dell recommends that customers upgrade to a secure version as soon as possible.

Affected Version(s)

NetWorker NVE NetWorker 19.6.1.2 Linux and prior releases, NetWorker 19.7.0.3 Linux and prior releases, 19.7.1 Linux

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.