CVE-2024-51534

Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on the server filesystem. Exploitation could lead to denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

History

07 Feb 2025, 19:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
References () https://www.dell.com/support/kbdoc/en-us/000279157/dsa-2025-022-security-update-for-dell-powerprotect-dd-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000279157/dsa-2025-022-security-update-for-dell-powerprotect-dd-multiple-vulnerabilities - Vendor Advisory
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
CWE CWE-29 CWE-22
First Time Dell
Dell data Domain Operating System

01 Feb 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-01 04:15

Updated : 2025-02-07 19:58


NVD link : CVE-2024-51534

Mitre link : CVE-2024-51534


JSON object : View

Products Affected

dell

  • data_domain_operating_system
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')