Description
Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink.
Problem types
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
Any version before 8.1.1
Credits
Dell would like to thank zzcentury from Ubisectech Sirius Team for reporting this issue.
References
www.dell.com/...-cloudlink-multiple-security-vulnerabilities