Improper Access Control in Dell SmartFabric Storage Software
CVE-2023-43072

4.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
5 October 2023

Summary

Dell SmartFabric Storage Software versions up to v1.4 are affected by an improper access control vulnerability in the command line interface (CLI). This flaw could allow a local, potentially unauthenticated attacker to exploit the system, granting them the ability to execute arbitrary shell commands. Organizations using affected versions are advised to apply security updates to mitigate the risks associated with this vulnerability. For detailed information and remediation guidance, refer to Dell's security advisory.

Affected Version(s)

Dell SmartFabric Storage Software v1.4.0 and prior

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.