ZeroHour

CVE-2019-3704

CVSS 3.0
7.8 high
EPSS
<1%p59
Published
()
Modified
Description

VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated malicious user could potentially execute arbitrary OS commands as root by exploiting this vulnerability.

Vendors
dell
Products
emc vnx2 firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.