CVE-2024-51532

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200q:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*

History

29 Jan 2025, 21:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
First Time Dell
Dell powerstore 9200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 3000t
Dell powerstore 1200t
Dell powerstore 7000t
Dell powerstore 1000t
Dell powerstore 5200t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 9000t
Dell powerstoreos
CPE cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200q:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-ie/000250483/dsa-2024-462-dell-powerstore-t-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-ie/000250483/dsa-2024-462-dell-powerstore-t-security-update-for-multiple-vulnerabilities - Vendor Advisory

19 Dec 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 02:15

Updated : 2025-01-29 21:06


NVD link : CVE-2024-51532

Mitre link : CVE-2024-51532


JSON object : View

Products Affected

dell

  • powerstore_9200t
  • powerstore_500t
  • powerstore_1200t
  • powerstoreos
  • powerstore_3000t
  • powerstore_3200q
  • powerstore_7000t
  • powerstore_9000t
  • powerstore_3200t
  • powerstore_5200t
  • powerstore_5000t
  • powerstore_1000t
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')