Improper Access Control in Dell SmartFabric Storage Software
CVE-2023-43072
4.4MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 5 October 2023
Summary
Dell SmartFabric Storage Software versions up to v1.4 are affected by an improper access control vulnerability in the command line interface (CLI). This flaw could allow a local, potentially unauthenticated attacker to exploit the system, granting them the ability to execute arbitrary shell commands. Organizations using affected versions are advised to apply security updates to mitigate the risks associated with this vulnerability. For detailed information and remediation guidance, refer to Dell's security advisory.
Affected Version(s)
Dell SmartFabric Storage Software v1.4.0 and prior
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved