Stack-based Buffer Overflow Vulnerability in Dell PowerProtect Data Manager
CVE-2023-44305
9.8CRITICAL
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 4 December 2023
Summary
The Dell PowerProtect Data Manager DM5500 version 5.14.0.0 has been identified to contain a stack-based buffer overflow vulnerability in the PPOE component. This flaw allows unauthenticated remote attackers to exploit the system by sending specially crafted input data. Successful exploitation can lead to a crash of the affected process, or potentially allow the execution of arbitrary code on the system, posing serious security risks for organizations reliant on this product for data protection.
Affected Version(s)
Dell PowerProtect Data Manager DM5500 Appliance DM5500 5.14 and below
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved