Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-25539

Опубликовано: 31 мая 2023
Источник: nvd
CVSS3: 8.4
CVSS3: 9.8
EPSS Низкий

Описание

Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:dell:networker:*:*:*:*:*:*:*:*
Версия до 19.7.0.4 (исключая)
cpe:2.3:a:dell:networker:19.7.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01123
Низкий

8.4 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-78

Связанные уязвимости

CVSS3: 8.4
github
больше 2 лет назад

Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity.

EPSS

Процентиль: 78%
0.01123
Низкий

8.4 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-78