PowerProtect DD Vulnerability Could Lead to Escalation of Privilege
CVE-2024-48010

7.2HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
8 November 2024

Summary

Dell PowerProtect DD versions prior to 8.1.0.0, along with specific earlier versions, are susceptible to an access control vulnerability. This issue allows remote attackers with high privileges to potentially exploit the vulnerability, leading to unauthorized escalation of privileges within the application. It is crucial for organizations using affected versions to apply recommended security updates promptly to mitigate risks associated with potential exploits.

Affected Version(s)

PowerProtect DD 7.7.1 <= 8.0.0.0

PowerProtect DD < 7.13.1.10

PowerProtect DD < 7.10.1.40

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.