Dell NetWorker Management Console Arbitrary Code Execution Vulnerability
Vulnerability
A vulnerability allowing arbitrary code execution has been identified in Dell NetWorker Management Console versions 19.11 through 19.11.0.3 and versions prior to 19.10.0.7. This vulnerability arises from improper neutralization of server-side input, which could be exploited by an unauthenticated attacker with local access to execute arbitrary code on the server.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of code on the server where NetWorker Management Console is running.
Remediation
Users can upgrade to version 19.11.0.4 or later. For versions prior to 19.10.0.7, version 19.10.0.7 or 19.11.0.4 can be installed. The latest versions can be downloaded from the Dell Support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
