OS Command Injection Vulnerability in Dell NetWorker Software
CVE-2023-25539
9.8CRITICAL
Summary
Dell NetWorker version 19.6.1.2 is vulnerable to an OS command injection flaw in the NetWorker client. This security issue allows remote unauthenticated attackers to execute arbitrary OS commands on the underlying system with the same privileges as the application. As a result, an attacker could gain complete control of the affected system. To mitigate this risk, Dell recommends that customers upgrade to a secure version as soon as possible.
Affected Version(s)
NetWorker NVE NetWorker 19.6.1.2 Linux and prior releases, NetWorker 19.7.0.3 Linux and prior releases, 19.7.1 Linux
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved