Description
Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Problem types
CWE-77: Improper Neutralization of Special Elements used in a Command (Command Injection)
Product status
Any version before 1.4.5 or later
Credits
Dell would like to thank zzcentury from Ubisectech Sirius Team for reporting this issue.
References
www.dell.com/...smartfabric-storage-software-vulnerabilities