CVE-2024-51534

Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on the server filesystem. Exploitation could lead to denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

History

07 Feb 2025, 19:58

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000279157/dsa-2025-022-security-update-for-dell-powerprotect-dd-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000279157/dsa-2025-022-security-update-for-dell-powerprotect-dd-multiple-vulnerabilities - Vendor Advisory
First Time Dell
Dell data Domain Operating System
CWE CWE-22
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
Summary
  • (es) Las versiones de Dell PowerProtect DD anteriores a DDOS 8.3.0.0, 7.10.1.50 y 7.13.1.20 contienen una vulnerabilidad Path Traversal. Un usuario local con pocos privilegios podría aprovechar esta vulnerabilidad para obtener una sobrescritura no autorizada de los archivos del sistema operativo almacenados en el sistema de archivos del servidor. La explotación podría provocar una denegación de servicio.

01 Feb 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-01 04:15

Updated : 2025-02-07 19:58


NVD link : CVE-2024-51534

Mitre link : CVE-2024-51534

CVE.ORG link : CVE-2024-51534


JSON object : View

Products Affected

dell

  • data_domain_operating_system
CWE
CWE-29

Path Traversal: '\..\filename'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')