Home

Description

Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on the server filesystem. Exploitation could lead to denial of service.

PUBLISHED Reserved 2024-10-29 | Published 2025-02-01 | Updated 2025-02-12 | Assigner dell




HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Problem types

CWE-29: Path Traversal: '\..\filename'

Product status

Default status
unaffected

7.7.1.0 (semver)
affected

7.7.1.0 (semver)
affected

7.7.1.0 (semver)
affected

References

www.dell.com/...ell-powerprotect-dd-multiple-vulnerabilities vendor-advisory

cve.org (CVE-2024-51534)

nvd.nist.gov (CVE-2024-51534)

Download JSON