Improper Access Control in Dell PowerProtect DD Products
CVE-2024-53295
7.8HIGH
Summary
An improper access control vulnerability exists in Dell PowerProtect DD that could be exploited by a local attacker with limited privileges. By leveraging this flaw, the attacker may gain the ability to escalate their privileges, potentially allowing unauthorized access to sensitive functions within the affected systems. This vulnerability is present in several versions of the product, highlighting the importance of keeping systems updated and implementing strict access controls.
Affected Version(s)
PowerProtect DD 7.7.1.0 <= 8.1.0.10
PowerProtect DD 7.13.1.0 <= 7.13.1.10
PowerProtect DD 7.10.1.0 <= 7.10.1.40
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved