CVE-2024-0168

Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands with root privileges.

Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:unity_operating_environment:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000222010/dsa-2024-042-dell-unity-dell-unity-vsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000222010/dsa-2024-042-dell-unity-dell-unity-vsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory

Information

Published : 2024-02-12 19:15

Updated : 2024-11-21 08:45


NVD link : CVE-2024-0168

Mitre link : CVE-2024-0168

CVE.ORG link : CVE-2024-0168


JSON object : View

Products Affected
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')