High
Cloud Mobility for Dell Storage 1.3.0 contains an RCE vulnerability. A nonprivileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a high severity issue; so Dell Technologies recommends customers to upgrade at the earliest opportunity.
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector |
CVE-2022-33936 | Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains a path traversal in the backup mechanism for the vApp. Any basic user may purposefully or accidentally exploit this vulnerability, leading to RCE with full take over of the system. | 8.0 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Cloud Mobility for Dell Storage 1.3.0 contains an RCE vulnerability. A nonprivileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a high severity issue; so Dell Technologies recommends customers to upgrade at the earliest opportunity.
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector |
CVE-2022-33936 | Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains a path traversal in the backup mechanism for the vApp. Any basic user may purposefully or accidentally exploit this vulnerability, leading to RCE with full take over of the system. | 8.0 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVE Addressed | Product | Affected Version | Updated Version | Link to Update |
CVE-2022-33936 | Cloud Mobility for Dell Storage | 1.3.0 | 1.3.1 | Amazon Marketplace: Cloud Mobility for Dell Storage Or VMware Marketplace |
CVE Addressed | Product | Affected Version | Updated Version | Link to Update |
CVE-2022-33936 | Cloud Mobility for Dell Storage | 1.3.0 | 1.3.1 | Amazon Marketplace: Cloud Mobility for Dell Storage Or VMware Marketplace |
We now reject any patterns in the restore tar file that start with an absolute path or contain .. anywhere in the file path.
Revision | Date | Description |
---|---|---|
1.0 | 2022-07-06 | Initial release |