CVE-2019-3704
—CVSS 3.0
7.8 high
EPSS
<1%p59
Published
()
Modified
Description
VNX Control Station in Dell EMC VNX2 OE for File versions prior to 8.1.9.236 contains OS command injection vulnerability. Due to inadequate restriction configured in sudores, a local authenticated malicious user could potentially execute arbitrary OS commands as root by exploiting this vulnerability.
- Vendors
- dell
- Products
- emc vnx2 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.