Dell PowerProtect DD Path Traversal Vulnerability Allowing Unauthorized File Overwrite
Vulnerability
A path traversal vulnerability has been identified in Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20. This vulnerability allows a local user with low privileges to exploit the issue and gain unauthorized access to overwrite operating system files on the server's filesystem. Such exploitation could result in a denial-of-service condition.
Impact
Exploitation of this vulnerability could lead to unauthorized overwriting of operating system files, potentially causing a denial-of-service condition on the affected system.
Remediation
Users can upgrade to Dell PowerProtect DD version 8.3.0.0 or later, or version 7.10.1.50 or later. Instructions for downloading the update are available on the Dell Support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
