Back to overview

CVE-2024-37143

CRITICAL
10.0
CVSS 3.1
Description
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and Dell Data Lakehouse versions prior to 1.2.0.0 contain an Improper Link Resolution Before File Access vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to execute arbitrary code on the system.

Metadata

CVE ID
CVE-2024-37143
State
PUBLISHED
Assigner
dell
Reserved
2024-06-03 12:10 UTC
Published
2024-12-10 02:25 UTC
Last updated
2024-12-11 17:16 UTC
Primary CWE
CWE-59
CWE-59: Improper Link Resolution Before File Access ('Link F…
Vendor / Product
Dell / Dell PowerFlex appliance
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (5)
VendorProductPlatformVersions
Dell Dell Data Lakehouse N/A < 1.2.0.0
Dell Dell InsightIQ N/A < 5.1.1
Dell Dell PowerFlex appliance N/A < 46.381.00, N/A < 46.376.00
Dell Dell PowerFlex custom node N/A < 4.6.1.0
Dell Dell PowerFlex rack N/A < 3.8.1.0, N/A < 3.7.6.0
Weakness (CWE)
CWESourceDescription
CWE-59 cna CWE-59: Improper Link Resolution Before File Access ('Link Following')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview