Description

Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or remote authenticated attacker could potentially exploit this vulnerability, leading to the ability to gain root-level access.

Published: 2023-10-05
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54264 Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or remote authenticated attacker could potentially exploit this vulnerability, leading to the ability to gain root-level access.
History

Thu, 19 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Dell Smartfabric Storage Software
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-19T18:52:12.000Z

Reserved: 2023-08-17T10:11:34.829Z

Link: CVE-2023-4401

cve-icon Vulnrichment

Updated: 2024-08-02T07:24:04.623Z

cve-icon NVD

Status : Modified

Published: 2023-10-05T18:15:13.087

Modified: 2024-11-21T08:35:04.300

Link: CVE-2023-4401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses