CVE-2024-25946
 
Severity Score
7.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.
Dell vApp Manager, las versiones anteriores a la 9.2.4.9 contienen una vulnerabilidad de inyección de comandos. Un atacante autorizado podría explotar esta vulnerabilidad y llevar a la ejecución de un comando insertado. Dell recomienda a los clientes actualizar lo antes posible.
*Credits:
Dell Technologies would like to thank 33a6099 for reporting these issues
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-02-13 CVE Reserved
- 2024-03-28 CVE Published
- 2024-03-29 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Virtual Appliance (vApp) Manager Search vendor "Dell" for product "Virtual Appliance (vApp) Manager" | < 9.2.4.9 Search vendor "Dell" for product "Virtual Appliance (vApp) Manager" and version " < 9.2.4.9" | en |
Affected
| ||||||
Dell Search vendor "Dell" | Virtual Appliance (vApp) Manager Search vendor "Dell" for product "Virtual Appliance (vApp) Manager" | < 9.2.4.6 Search vendor "Dell" for product "Virtual Appliance (vApp) Manager" and version " < 9.2.4.6" | en |
Affected
| ||||||
Dell Search vendor "Dell" | Virtual Appliance (vApp) Manager Search vendor "Dell" for product "Virtual Appliance (vApp) Manager" | < 5978 Search vendor "Dell" for product "Virtual Appliance (vApp) Manager" and version " < 5978" | en |
Affected
|